PT-2026-28274 · Mlflow · Mlflow

CVE-2025-15381

·

Publicado

2026-03-27

·

Atualizado

2026-07-13

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions mlflow/mlflow (affected versions not specified)
Description When the basic-auth application is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, even those with NO PERMISSIONS on an experiment, to read trace information and create assessments for traces they should not have access to. This impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. The issue affects deployments using mlflow server --app-name=basic-auth. The vulnerable endpoints are tracing and assessment endpoints. The NO PERMISSIONS role is a factor in the exploitation of this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15381
GHSA-G6PG-52VF-843H
PYSEC-2026-2657

Produtos afetados

Mlflow