Description
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2882 | An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. |
Github GHSA |
GHSA-4qq5-mxxx-m6gg | MLflow authentication requirement bypass can allow a user to arbitrarily create an account |
References
History
No history.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-09-04T20:22:09.674Z
Reserved: 2023-11-08T09:11:22.613Z
Link: CVE-2023-6014
Updated: 2024-08-02T08:21:17.031Z
Status : Modified
Published: 2023-11-16T21:15:09.267
Modified: 2024-11-21T08:42:58.907
Link: CVE-2023-6014
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA