VDB
KO
CRITICAL 9.1

GHSA-4qq5-mxxx-m6gg

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

Details

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mlflow
Introduced in: 0 Fixed in: 2.8.0
Fix pip install --upgrade 'mlflow>=2.8.0'

References