CPE
high
advisory
Multiple Vulnerabilities in MLflow Enabling Arbitrary Code Execution
2 TTPs 2 CVEsMultiple vulnerabilities in MLflow, identified as CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978, allow remote attackers to execute arbitrary code due to improper input validation and insecure deserialization.
MLflow
2t
2c
high
advisory
MLflow Statsmodels Flavor Security Control Bypass
2 TTPs 3 CVEsThe MLflow 'statsmodels' flavor fails to implement the 'MLFLOW_ALLOW_PICKLE_DESERIALIZATION' security control, allowing unauthenticated attackers to achieve arbitrary code execution via crafted pickle model artifacts.
PoC
mlflow
2t
3c
updated
critical
advisory
MLflow Tracking Server Unauthenticated Full-Read SSRF via Webhook Delivery
1 rule 2 TTPs 2 CVEsMLflow Tracking Server versions prior to 3.15.0 are vulnerable to an unauthenticated full-read SSRF attack because the webhook delivery mechanism follows unvalidated HTTP redirects, allowing attackers to exfiltrate internal data or interact with local services.
MLflow Tracking Server +2
ssrf
mlflow
web-vulnerability
1r
2t
2c
updated