CVE Vulnerabilities

CVE-2023-6014

Use of GET Request Method With Sensitive Query Strings

Published: Nov 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
MlflowLfprojects**

Potential Mitigations

References