CVE-2025-1474 - CERT CVE
ID CVE-2025-1474
Sažetak In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Reference
CVSS
Base: 3.8
Impact: 2.5
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 27-03-2025 - 15:36
Objavljeno 20-03-2025 - 10:15