CVE-2025-1473

Source
https://cve.org/CVERecord?id=CVE-2025-1473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-1473
Aliases
Published
2025-03-20T10:10:20.747Z
Modified
2026-07-22T03:36:09.707395Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
CSRF in mlflow/mlflow
Details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1473.json",
    "cwe_ids": [
        "CWE-352"
    ]
}
References

Affected packages

Git / github.com/mlflow/mlflow

Affected ranges

Type
GIT
Repo
https://github.com/mlflow/mlflow
Events
Database specific
{
    "cpe": "cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.17.0"
        },
        {
            "fixed": "2.20.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Database specific

vanir_signatures_modified
"2026-07-22T03:36:09Z"
vanir_signatures
[
    {
        "target": {
            "file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
        },
        "id": "CVE-2025-1473-08972991",
        "digest": {
            "line_hashes": [
                "337790989433725412038630751075056464335",
                "249170095474537496017572805809341887872",
                "265617740387335315124281718573196279907",
                "248520135169040194161556615045875925829"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/mlflow/mlflow/commit/cb69262fe58a0689056f68f4368d1b7704296c5c"
    },
    {
        "target": {
            "file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
        },
        "id": "CVE-2025-1473-37000409",
        "digest": {
            "line_hashes": [
                "269405291552122194346538507471132020444",
                "205342522101935226192695116558528053284",
                "251669814725538675598117859072449257571",
                "67712642428662465909585702026871474399"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/mlflow/mlflow/commit/cb69262fe58a0689056f68f4368d1b7704296c5c"
    },
    {
        "target": {
            "function": "doGet",
            "file": "mlflow/java/scoring/src/main/java/org/mlflow/sagemaker/ScoringServer.java"
        },
        "id": "CVE-2025-1473-4af8f3cc",
        "digest": {
            "function_hash": "162733977311982238867207374626216451371",
            "length": 189.0
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/mlflow/mlflow/commit/cb69262fe58a0689056f68f4368d1b7704296c5c"
    },
    {
        "target": {
            "function": "testScoringServerWithValidPredictorRespondsToVersionCorrectly",
            "file": "mlflow/java/scoring/src/test/java/org/mlflow/ScoringServerTest.java"
        },
        "id": "CVE-2025-1473-c4c4ffe7",
        "digest": {
            "function_hash": "6287921176302245627998445760826141095",
            "length": 483.0
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/mlflow/mlflow/commit/cb69262fe58a0689056f68f4368d1b7704296c5c"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1473.json"