Skip to content
MLflowGHSA-4rj2-9gcx-5qhx

MLflow has Weak Password Requirements

Low3.8CVE-2025-1474 · Published Mar 20, 2025 · updated Apr 9, 2025

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.19.02.19.0
Details and references

More MLflow advisories

All MLflow
Advisory
MLFlow SSRF via gateway_proxy_handler
Medium5.8Jun 23, 2025
MLflow Cross-Site Request Forgery (CSRF) vulnerability
Medium5.4Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.9Mar 20, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High7.5Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.3Mar 20, 2025
MLflow's excessive directory permissions allow local privilege escalation
High7.0Nov 25, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.