Headline
GHSA-4qq5-mxxx-m6gg: MLflow authentication requirement bypass can allow a user to arbitrarily create an account
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
Critical severity GitHub Reviewed Published Nov 16, 2023 to the GitHub Advisory Database • Updated Nov 17, 2023
Related news
CVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.