mlflow
MLflow is an open source platform for the complete machine learning lifecycle
Security Advisories for mlflow in pypi
High
about 1 month ago
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
pypi
mlflow
Critical
about 2 months ago
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
pypi
mlflow
Low
4 months ago
MLflow: Deterministic sampling in dataset digest enables predictable collisions
pypi
mlflow
Critical
4 months ago
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
pypi
mlflow
Moderate
4 months ago
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
pypi
mlflow
Critical
4 months ago
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
pypi
mlflow
Moderate
4 months ago
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
pypi
mlflow
Critical
5 months ago
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
pypi
mlflow
High
5 months ago
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
pypi
mlflow
Moderate
6 months ago
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
pypi
mlflow
Moderate
6 months ago
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
pypi
mlflow
Critical
6 months ago
mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
pypi
mlflow
Critical
6 months ago
Mlflow: Command Injection when serving models with enable_mlserver=True
pypi
mlflow
Critical
7 months ago
MLflow Use of Default Password Authentication Bypass Vulnerability
pypi
mlflow
High
7 months ago
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
pypi
mlflow
High
8 months ago
mlflow Creates of Temporary File in Directory with Insecure Permissions
pypi
mlflow
High
9 months ago
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
pypi
mlflow
High
11 months ago
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
pypi
mlflow
High
11 months ago
MLflow Weak Password Requirements Authentication Bypass Vulnerability
pypi
mlflow
High
almost 2 years ago
MLflow's excessive directory permissions allow local privilege escalation
pypi
mlflow
Critical
over 2 years ago
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
pypi
mlflow
Critical
almost 3 years ago
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
pypi
mlflow
Critical
almost 3 years ago
Remote Code Execution due to Full Controled File Write in mlflow
pypi
mlflow
Critical
over 3 years ago
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
pypi
mlflow
Moderate
over 3 years ago
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
pypi
mlflow
Critical
over 3 years ago
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
pypi
mlflow