CVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.88%
- CWE
- CWE-598
- Published
- 2023-11-16
- Last modified
- 2026-03-13
Affected products
- mlflow mlflow/mlflow
Weakness type
Related vulnerabilities
- CVE-2021-36328 — Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may
- CVE-2020-5331 — RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2019-18573 — The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Ses
- CVE-2025-26473 — Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
- CVE-2022-22551 — DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a
- CVE-2021-21594 — Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerab
- CVE-2024-31206 — Use of Unencrypted HTTP Request in dectalk-tts