VDB
KO
CRITICAL 10.0

GHSA-f798-qm4r-23r5

MLflow allowed arbitrary files to be PUT onto the server

Details

MLflow allowed arbitrary files to be PUT onto the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mlflow
Introduced in: 0 Fixed in: 2.8.1
Fix pip install --upgrade 'mlflow>=2.8.1'

References