漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Access Control in mlflow/mlflow
Vulnerability Description
MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`. This allows any authenticated user, regardless of their assigned permissions, to enumerate all gateway secrets, endpoints, and model definitions. This vulnerability exposes sensitive information, such as API keys, endpoint configurations, and proprietary model definitions, to unauthorized users.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
MLflow 安全漏洞
Vulnerability Description
MLflow是MLflow开源的一个简化机器学习开发的平台,包括跟踪实验、将代码打包成可重复的运行以及共享和部署模型。 MLflow 3.9.0版本存在安全漏洞,该漏洞源于基本身份验证模式下未对多个Gateway API列表端点强制执行授权检查,可能导致任何经过身份验证的用户枚举所有网关密钥、端点和模型定义,泄露API密钥、端点配置和专有模型定义等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A