CVE-2023-6014.yaml
1 info: 2 name: mlflow 3 cve: CVE-2023-6014 4 summary: MLflow 认证绕过漏洞允许用户任意创建账户 5 details: | 6 攻击者能够绕过任何认证要求,在 MLflow 中任意创建账户。 7 cvss: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 8 severity: CRITICAL 9 security_advise: 升级到 mlflow >= 2.8.0 版本以解决此问题。 10 rule: version < "2.8.0" 11 references: 12 - https://nvd.nist.gov/vuln/detail/CVE-2023-6014 13 - https://github.com/mlflow/mlflow/issues/9669 14 - https://github.com/mlflow/mlflow/pull/9700 15 - https://github.com/mlflow/mlflow/commit/32de2154ef9f946160e5dc01a4d8a449dd0bd259 16 - https://github.com/mlflow/mlflow 17 - https://github.com/mlflow/mlflow/releases/tag/v2.8.0 18 - https://huntr.com/bounties/3e64df69-ddc2-463e-9809-d07c24dc1de4