Loading HuntDB...

MLflow

2 Products 41 CVEs

CVE Severity Distribution (All Time)

Critical
14
High
23
Medium
4
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-2928 HIGH 1 year, 3 months ago

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vu…

CVE-2024-0520 CRITICAL 1 year, 3 months ago

A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS comm…

CVE-2024-3099 MEDIUM 1 year, 3 months ago

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c…

CVE-2024-37061 HIGH 1 year, 3 months ago

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…

CVE-2024-37060 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe…

CVE-2024-37059 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc…

CVE-2024-37058 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch…

CVE-2024-37057 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten…

CVE-2024-37056 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light…

CVE-2024-37055 HIGH 1 year, 3 months ago

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar…

Related Security News

CVE-2024-2928: MLflow Local File Inclusion via URI Fragment Manipulation
2025-05-15 15:41 Offsec.com

Read about an LFI vulnerability disclosed in MLflow which allowed unauthenticated remote attackers to read arbitrary files by exploiting URI fragments containing directory traversal sequences. The po…