An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
An attacker can overwrite any file on the server hosting MLflow without any authentication.
MLflow allowed arbitrary files to be PUT onto the server.
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on t…
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.…
FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C…
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vul…
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.