An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
References
Link | Resource |
---|---|
https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security | Exploit Press/Media Coverage |
Configurations
History
No history.
Information
Published : 2023-12-05 07:15
Updated : 2023-12-11 15:32
NVD link : CVE-2023-43472
Mitre link : CVE-2023-43472
CVE.ORG link : CVE-2023-43472
JSON object : View
Products Affected
lfprojects
- mlflow
CWE