Vulnerabilities in mlflow

76 results
Vexday analysis

O MLflow acumula 54 CVEs catalogadas, das quais 21 são classificadas como críticas — volume que exige atenção contínua em ambientes de MLOps. Embora nenhuma vulnerabilidade conste atualmente no catálogo KEV da CISA, o que situa a taxa de exploração ativa abaixo da média geral do catálogo, o score EPSS de 0,8972 associado a CVE-2023-6909 indica probabilidade elevada de exploração para essa vulnerabilidade específica, tornando-a prioridade imediata de remediação. A presença de 3 CVEs com PoC pública e 11 falhas surgidas nos últimos 90 dias demonstra uma superfície de ataque em expansão recente. O tipo de falha mais recorrente (CWE-29, relativo a travessia de caminho com elementos de sequência de diretório) sugere fragilidades no tratamento de caminhos de arquivo, padrão que tende a ser explorado em plataformas de experimentação e registro de modelos com acesso a sistemas de arquivos locais ou remotos.

CVE-2024-37060HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously craftEPSS 0.8%CVE-2024-3573CRITICALLocal File Inclusion (LFI) via Scheme Confusion in mlflow/mlflowEPSS 0.7%CVE-2024-1594HIGHLocal File Read via Path Traversal in mlflow/mlflowEPSS 0.7%CVE-2024-37054HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploadEPSS 0.7%CVE-2024-1593HIGHPath Traversal via Parameter Smuggling in mlflow/mlflowEPSS 0.7%CVE-2024-6838MEDIUMUncontrolled Resource Consumption in mlflow/mlflowEPSS 0.7%CVE-2024-37055HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-37052HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2024-37056HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-37059HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2024-37058HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2024-37057HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uplEPSS 0.6%CVE-2024-37053HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2023-1176MEDIUMAbsolute Path Traversal in mlflow/mlflowEPSS 0.6%CVE-2025-15036CRITICALPath Traversal Vulnerability in mlflow/mlflowEPSS 0.6%CVE-2026-8147HIGHAuthorization Bypass in mlflow/mlflowEPSS 0.5%CVE-2026-4035HIGHEnvironment Variable Resolution Vulnerability in mlflow/mlflowEPSS 0.5%CVE-2024-3099MEDIUMDenial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflowEPSS 0.4%CVE-2026-2734MEDIUMAuthorization Bypass in SearchModelVersions in mlflow/mlflowEPSS 0.4%CVE-2026-2611CRITICALImproper Origin Validation in mlflow/mlflowEPSS 0.4%