CVE-2023-6014: MLflow Authentication Bypass
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.
Other sources
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-6014?
CVE-2023-6014 is a vulnerability that allows an attacker to create an account in MLflow without authentication.
How severe is CVE-2023-6014?
CVE-2023-6014 has a severity level of critical, with a CVSS score of 9.1.
Which software is affected by CVE-2023-6014?
MLflow version up to and including 2.5.0 is affected by CVE-2023-6014.
How can I fix CVE-2023-6014?
To fix CVE-2023-6014, update to a version of MLflow that is higher than 2.5.0.
Where can I find more information about CVE-2023-6014?
You can find more information about CVE-2023-6014 on the following references: [Huntr](https://huntr.com/bounties/3e64df69-ddc2-463e-9809-d07c24dc1de4), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-6014), [GitHub Advisory](https://github.com/advisories/GHSA-4qq5-mxxx-m6gg).