Описание
Information exposure in MLflow
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Пакеты
Наименование
mlflow
pip
Затронутые версииВерсия исправления
< 2.9.0
2.9.0
Связанные уязвимости
CVSS3: 7.5
nvd
около 2 лет назад
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.