CVE-2025-1473: CSRF in mlflow/mlflow
Published Mar 20, 2025
·Updated
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
Affected Software
3 affected componentsFixes available
MLflow MLflow>=2.17.0<=2.20.1
pip/mlflow>=2.17.0<2.20.3
2.20.3
Lfprojects Mlflow>=2.17.0<2.20.1
Remediation
Event History
Mar 20, 2025
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyAffected Software
Advisory Published
via GitHub·12:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-1473?
CVE-2025-1473 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
Who is affected by CVE-2025-1473?
CVE-2025-1473 affects users of mlflow/mlflow versions from 2.17.0 to 2.20.1.
3
How do I fix CVE-2025-1473?
To fix CVE-2025-1473, upgrade to mlflow version 2.20.3 or later.
4
What kind of attacks can occur due to CVE-2025-1473?
CVE-2025-1473 allows an attacker to create unauthorized accounts that can perform actions on behalf of the malicious user.
5
What features are impacted by CVE-2025-1473?
The Signup feature of mlflow/mlflow is specifically impacted by CVE-2025-1473.