MLflowGHSA-4rj2-9gcx-5qhx
MLflow has Weak Password Requirements
Low3.8CVE-2025-1474 · Published Mar 20, 2025 · updated Apr 9, 2025
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.19.0 | 2.19.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-521
- Also known as
- BIT-mlflow-2025-1474, CVE-2025-1474, PYSEC-2025-17
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 232025 | MLFlow SSRF via gateway_proxy_handler | Medium5.8 | 2.22.2+1 more |
| Mar 202025 | MLflow Cross-Site Request Forgery (CSRF) vulnerability | Medium5.4 | 2.20.3 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability | Medium5.9 | No fix yet |
| Mar 202025 | MLflow has a Local File Read/Path Traversal in dbfs | High7.5 | 2.17.0rc0 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability | Medium5.3 | No fix yet |
| Nov 252024 | MLflow's excessive directory permissions allow local privilege escalation | High7.0 | 2.16.0 |