An attacker can overwrite any file on the server hosting MLflow without any authentication.
2023-11-16T16:15:34.880
2024-11-21T08:42:59.413
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lfprojects | mlflow | - | Yes |