MEDIUM 5.5
PYSEC-2025-17
상세
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / mlflow
최초 영향 버전:
0 수정 버전: 149c9e18aa219bc47e86b432e130e467a36f4a17 수정
pip install --upgrade 'mlflow>=149c9e18aa219bc47e86b432e130e467a36f4a17'