An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
2023-11-16T21:15:09.267
2024-11-21T08:42:58.907
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | * | Yes |