7.5
CVSSv3

CVE-2023-43472

Published: 05/12/2023 Updated: 11/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue in MLFlow versions 2.8.1 and before allows a remote malicious user to obtain sensitive information via a crafted request to REST API.

Vulnerable Product Search on Vulmon Subscribe to Product

lfprojects mlflow