VDB
KO
HIGH 7.5

GHSA-wqxf-447m-6f5f

Information exposure in MLflow

Details

An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mlflow
Introduced in: 0 Fixed in: 2.9.0
Fix pip install --upgrade 'mlflow>=2.9.0'

References