ZDI-25-932: MLflow Weak Password Requirements Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-11200.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-932?
The severity of ZDI-25-932 is rated as 8.1 according to the CVSS scale.
How do I fix ZDI-25-932?
To fix ZDI-25-932, it is recommended to update to the latest patched version of MLflow.
What kind of vulnerability is ZDI-25-932?
ZDI-25-932 is a remote authentication bypass vulnerability in MLflow.
Who is affected by ZDI-25-932?
MLflow installations that do not implement adequate authentication are affected by ZDI-25-932.
Can ZDI-25-932 be exploited without authentication?
Yes, ZDI-25-932 can be exploited without requiring any authentication.