First published: Thu Nov 16 2023(Updated: )
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.
Affected Software | Affected Version | How to fix |
---|---|---|
pip/mlflow | <=2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-4qq5-mxxx-m6gg is critical with a severity value of 9.1.
GHSA-4qq5-mxxx-m6gg affects MLflow versions up to and including 2.5.0.
CVE-2023-6014 is a vulnerability associated with GHSA-4qq5-mxxx-m6gg.
An attacker can arbitrarily create an account in MLflow bypassing any authentication requirement with GHSA-4qq5-mxxx-m6gg.
More information about GHSA-4qq5-mxxx-m6gg can be found at the following references: [link1], [link2], [link3].