HIGH 7.5 PyPI
Information exposure in MLflow
GHSA-wqxf-447m-6f5f · BIT-mlflow-2023-43472 · CVE-2023-43472
Published · Modified
Description
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-43472
- PACKAGE https://github.com/mlflow/mlflow
- WEB https://mlflow.org/news/2023/12/06/2.9.0-release/index.html
- WEB https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security
Ready to move
Start Securing
Free, no credit card | First findings in minutes