Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rj2-9gcx-5qhx

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.8

Описание

MLflow has Weak Password Requirements

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.

Пакеты

Наименование

mlflow

pip
Затронутые версииВерсия исправления

< 2.19.0

2.19.0

EPSS

Процентиль: 26%
0.00091
Низкий

3.8 Low

CVSS3

Дефекты

CWE-521

Связанные уязвимости

CVSS3: 5.5
nvd
11 месяцев назад

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.

EPSS

Процентиль: 26%
0.00091
Низкий

3.8 Low

CVSS3

Дефекты

CWE-521