mlflow vulnerabilities

MLflow is an open source platform for the complete machine learning lifecycle

  • latest version

    3.4.0

  • first published

    7 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mlflow package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Server-side Request Forgery (SSRF)

    [,3.0.0)
    • M
    Missing Input Length Validation

    [,2.21.0)
    • H
    Allocation of Resources Without Limits or Throttling

    [,3.1.1)
    • M
    Weak Password Requirements

    [,2.19.0rc0)
    • H
    Cross-site Request Forgery (CSRF)

    [,2.20.2)
    • H
    Relative Path Traversal

    [,2.17.0rc0)
    • H
    Time-of-check Time-of-use (TOCTOU) Race Condition

    [,2.16.0)
    • H
    Arbitrary Code Injection

    [,2.15.0)
    • M
    Undefined Behavior

    [,2.11.3)
    • H
    Improper Access Control

    [,2.11.3)
    • C
    Remote Code Execution (RCE)

    [,2.9.0)
    • H
    Deserialization of Untrusted Data

    [1.27.0,)
    • H
    Deserialization of Untrusted Data

    [0.5.0,)
    • H
    Improper Control of Generation of Code ('Code Injection')

    [1.11.0,)
    • H
    Deserialization of Untrusted Data

    [2.5.0,)
    • H
    Deserialization of Untrusted Data

    [2.0.0rc0,)
    • H
    Deserialization of Untrusted Data

    [1.23.0,)
    • H
    Deserialization of Untrusted Data

    [1.24.0,)
    • H
    Deserialization of Untrusted Data

    [1.1.0,)
    • H
    Deserialization of Untrusted Data

    [0.9.0,)
    • H
    Path Traversal

    [,2.11.2)[2.12.0,2.12.1)
    • M
    Improper Access Control

    [,2.12.1)
    • H
    Path Traversal

    [,2.12.1)
    • H
    Path Traversal

    [,2.13.0)
    • H
    Path Traversal

    [,2.11.3)
    • H
    Path Traversal

    [,2.11.3)
    • H
    Path Traversal

    [,2.11.3)[2.12.0,2.12.1)
    • C
    Path Traversal

    [,2.10.0)
    • M
    Cross-site Scripting (XSS)

    [,2.10.0)
    • H
    Arbitrary Code Injection

    [,2.10.0)
    • C
    Improper Access Control

    [,2.9.2)
    • H
    Directory Traversal

    [,2.9.2)
    • H
    Arbitrary File Read

    [,2.10.0)
    • H
    Server-Side Request Forgery (SSRF)

    [,2.9.2)
    • H
    Command Injection

    [,2.9.2)
    • H
    Directory Traversal

    [,2.9.2)
    • H
    Directory Traversal

    [,2.9.2)
    • H
    Path Traversal

    [,2.9.2)
    • C
    Improper Neutralization of Special Elements Used in a Template Engine

    [,2.9.2)
    • M
    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    [,2.9.0)
    • M
    Information Exposure

    [2.0.0,2.9.0)
    • C
    OS Command Injection

    [,2.9.0)
    • C
    Use of GET Request Method With Sensitive Query Strings

    [,2.8.0)
    • H
    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    [,2.8.1)
    • H
    Command Injection

    [0,2.6.0)
    • C
    Directory Traversal

    [2.2.0,2.5.0)
    • H
    Directory Traversal

    [,2.4.1)
    • C
    Arbitrary File Read

    [,2.3.0)
    • H
    Directory Traversal

    [,2.0.0rc0)
    • C
    Relative Path Traversal

    [,2.3.1)
    • C
    Access Restriction Bypass

    [,2.3.1)
    • H
    Relative Path Traversal

    [,2.3.1)
    • M
    Access Restriction Bypass

    [,2.2.0)
    • C
    Improper Access Control

    [,2.2.1)
    • H
    Insecure Temporary File

    [,1.23.1)

    Package versions

    155 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    3.4.017 Sep, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.4.0rc012 Sep, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.3.227 Aug, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.3.120 Aug, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.3.019 Aug, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.3.0rc013 Aug, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.2.05 Aug, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.2.0rc029 Jul, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.1.423 Jul, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L
    3.1.322 Jul, 2025
    • 0
      C
    • 9
      H
    • 0
      M
    • 0
      L