In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators.
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N약점 (CWE)
- CWE-284
부적절한 접근 제어 — 접근 통제가 미흡해 무단 접근 허용.
상세 설명
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the _before_request handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- lfprojects mlflow< 3.14.0other
영향받는 구성 (CPE) 1
- lfprojects mlflow< 3.14.0cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
참고 자료 2
- https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5ExploitThird Party Advisory
링크 내용 불러오는 중…