GHSA-969w-gqqr-g6j3

Suggest an improvement
Source
https://github.com/advisories/GHSA-969w-gqqr-g6j3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-969w-gqqr-g6j3
Aliases
Published
2025-03-20T12:32:53Z
Modified
2025-03-22T00:05:49.942173Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
MLflow Cross-Site Request Forgery (CSRF) vulnerability
Details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.

Database specific
{
    "nvd_published_at": "2025-03-20T10:15:53Z",
    "cwe_ids": [
        "CWE-352"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-21T23:38:57Z"
}
References

Affected packages

PyPI / mlflow

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.17.0
Fixed
2.20.3

Affected versions

2.*

2.17.0
2.17.1
2.17.2
2.18.0rc0
2.18.0
2.19.0rc0
2.19.0
2.20.0rc0
2.20.0
2.20.1
2.20.2