Vulnerabilidades em MLflow

72 resultados
Análise Vexday

MLflow apresenta 14 vulnerabilidades catalogadas, predominantemente ligadas a desserialização insegura (CWE-502), mas sem nenhuma exploração ativa registrada ou crítica máxima identificada. O risco atual é contido pela ausência de ataques em campanha, embora a natureza das falhas (desserialização) represente vetor potencial em ambientes expostos; nenhuma vulnerabilidade foi publicada nos últimos 90 dias.

CVE-2023-6909HIGHPath Traversal: '\..\filename' in mlflow/mlflowEPSS 89.7%CVE-2023-1177CRITICALPath Traversal: '\..\filename' in mlflow/mlflowEPSS 69.7%CVE-2023-3765CRITICALAbsolute Path Traversal in mlflow/mlflowEPSS 67.5%CVE-2023-6018CRITICALMLflow Arbitrary File WriteEPSS 47.6%CVE-2024-3848HIGHPath Traversal Bypass in mlflow/mlflowEPSS 43.3%CVE-2025-11201HIGHMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution VulnerabilityEPSS 27.0%CVE-2024-2928HIGHLocal File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflowEPSS 21.8%CVE-2026-2652HIGHAuthentication Bypass in mlflow/mlflowEPSS 18.9%CVE-2025-0453MEDIUMDenial of Service through Batched Queries in GraphQL in mlflow/mlflowEPSS 10.4%CVE-2023-2780CRITICALPath Traversal: '\..\filename' in mlflow/mlflowEPSS 6.4%CVE-2023-6015CRITICALMLflow Arbitrary File UploadEPSS 4.4%CVE-2026-0545HIGHMissing Authentication for Critical Function in mlflow/mlflowEPSS 4.4%CVE-2023-2356CRITICALRelative Path Traversal in mlflow/mlflowEPSS 4.2%CVE-2023-6977CRITICALPath Traversal: '\..\filename'EPSS 3.9%CVE-2023-6831HIGHPath Traversal: '\..\filename' in mlflow/mlflowEPSS 3.3%CVE-2024-1483HIGHPath Traversal Vulnerability in mlflow/mlflowEPSS 2.7%CVE-2024-8859HIGHPath Traversal in mlflow/mlflowEPSS 2.6%CVE-2024-0520CRITICALRemote Code Execution due to Full Controlled File Write in mlflow/mlflowEPSS 2.4%CVE-2023-6975CRITICALPath Traversal: '\..\filename'EPSS 2.0%CVE-2025-15379CRITICALCommand Injection in mlflow/mlflowEPSS 2.0%