MLflow Tracking Server versions prior to 3.15.0 are vulnerable to an unauthenticated full-read SSRF attack because the webhook delivery mechanism follows unvalidated HTTP redirects, allowing attackers to exfiltrate internal data or interact with local services.
MLflow Tracking Server +2
ssrf
mlflow
web-vulnerability
1r
2t
2c
updated