PT-2026-53097 · Mlflow · Mlflow
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MLflow versions up to 4666cffc7912ea606d592fc38d6a75e2935f65e7
Description
An issue exists within the Experiment-scoped Label Schema CRUD API where a function lacks proper authorization. This allows a remote attacker to perform unauthorized manipulations, although the attack is characterized by high complexity and is difficult to exploit.
Recommendations
Update to a version where the labeling schema pull request has been merged and authorization handlers have been implemented.
Exploit
Fix
DoS
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mlflow