HIGH 7.5
GHSA-wqxf-447m-6f5f
Information exposure in MLflow
Details
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-43472 [ADVISORY]
- https://github.com/mlflow/mlflow [PACKAGE]
- https://mlflow.org/news/2023/12/06/2.9.0-release/index.html [WEB]
- https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security [WEB]