lfprojects mlflow
65 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
/ajax-api/3.0/jobs/* are not protected by authentication or authorization whenenable_mlserver=True. The model_uri is embextract_archive_to_dir function within the `mlflow/pyfunc/dbconnect_artifact_cache.basic-auth app is enabled, tracing and assessment endpoints are not protected b/graphql endpoint is vulnerable to a denial of service attack. An attacker can create largeartifact_location_create_model_version() function within server/handlers.py of the mlflow/mlflow r