CVE-2025-0453

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:2.17.2:*:*:*:*:*:*:*

History

02 Apr 2025, 16:10

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:lfprojects:mlflow:2.17.2:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Lfprojects
Lfprojects mlflow
References () https://huntr.com/bounties/788327ec-714a-4d5c-83aa-8df04dd7612b - () https://huntr.com/bounties/788327ec-714a-4d5c-83aa-8df04dd7612b - Exploit, Third Party Advisory

20 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-400

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-04-02 16:10


NVD link : CVE-2025-0453

Mitre link : CVE-2025-0453


JSON object : View

Products Affected

lfprojects

  • mlflow