CVE-2023-43472
HIGH7.5EPSS 72.8%Information exposure in MLflow
Published: 12/5/2023Modified: 4/3/2025
Description
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Affected packages (2)
- Bitnami/mlflowfrom 0, < 2.8.2
- PyPI/mlflowfrom 0, < 2.9.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
References (4)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-43472
- PATCHhttps://github.com/mlflow/mlflow
- WEBhttps://mlflow.org/news/2023/12/06/2.9.0-release/index.html
- WEBhttps://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security