GPU VulnDB

Database/AI/ML frameworks & serving

MLflow: Arbitrary account creation bypassing authentication

CVE-2023-6014AI/ML frameworks & servingcurated

Impact

Arbitrary account creation bypassing authentication

Who can reach it

Unauthenticated network to the tracking server

What to do

Upgrade; the basic-auth plugin is not a boundary

Fleet impact

How widespread

Common - same MLflow footprint; this is the incomplete-fix follow-on

Cost to remediate

daemon-restart - server upgrade, plus rotation of everything the server could reach

Why it hits the whole fleet

Basic-auth bypass on the tracking server, so the one control that was supposed to contain the previous LFI does not hold; full model-registry and artifact-store compromise

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.