ZeroHour

CVE-2025-15381

PoC
CVSS 3.1
7.1 high
EPSS
<1%p26
Published
()
Modified
Description

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.

Vendors
lfprojects
Products
mlflow
Weakness
CWE-200, CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.