Описание
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
Ссылки
- Patch
- ExploitIssue TrackingMitigation
- Issue TrackingPatch
- Release Notes
- ExploitVendor Advisory
- US Government Resource
Уязвимые конфигурации
EPSS
9.3 Critical
CVSS3
Дефекты
Связанные уязвимости
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Уязвимость функции _validate_webhook_url() файла mlflow/utils/validation.py платформы управления жизненным циклом моделей машинного обучения MLflow, позволяющая нарушителю осуществить SSRF-атаку и получить несанкционированный доступ к защищаемой информации
EPSS
9.3 Critical
CVSS3