Skip to content
MLflowGHSA-4qq5-mxxx-m6gg

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

Critical9.1CVE-2023-6014 · Published Nov 16, 2023 · updated Jun 29, 2026

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.8.02.8.0
Details and references

More MLflow advisories

All MLflow
Advisory
Path traversal in MLflow
High8.8Dec 13, 2023
Jinja2 template injection in mlflow
High8.8Dec 12, 2023
Cross-site Scripting (XSS) in MLflow
Medium6.5Dec 7, 2023
Information exposure in MLflow
High7.5Dec 5, 2023
Remote Code Execution due to Full Controled File Write in mlflow
Critical10.0Nov 16, 2023
MLflow allowed arbitrary files to be PUT onto the server
Critical10.0Nov 16, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.