CVE-2023-43472

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
11/12/2023

Description

An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* 2.8.1 (including)