CVE-2023-43472: Infoleak
Published Dec 5, 2023
·Updated
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Affected Software
2 affected componentsFixes available
pip/mlflow<2.9.0
2.9.0
Lfprojects Mlflow<=2.8.1
Event History
Dec 5, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
09:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-43472?
CVE-2023-43472 is categorized as a high severity vulnerability.
2
How do I fix CVE-2023-43472?
To fix CVE-2023-43472, upgrade MLFlow to version 2.9.0 or later.
3
Which versions of MLFlow are affected by CVE-2023-43472?
MLFlow versions 2.8.1 and earlier are affected by CVE-2023-43472.
4
What kind of information can an attacker obtain through CVE-2023-43472?
An attacker can obtain sensitive information via a crafted request to the MLFlow REST API due to CVE-2023-43472.
5
Is this vulnerability exploitable remotely in CVE-2023-43472?
Yes, CVE-2023-43472 allows remote attackers to exploit the vulnerability.