Описание
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Ссылки
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.19.0 (исключая)
cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00091
Низкий
3.8 Low
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-521
Связанные уязвимости
EPSS
Процентиль: 26%
0.00091
Низкий
3.8 Low
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-521