CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

27 Mar 2025, 15:36

Type Values Removed Values Added
References () https://github.com/mlflow/mlflow/commit/149c9e18aa219bc47e86b432e130e467a36f4a17 - () https://github.com/mlflow/mlflow/commit/149c9e18aa219bc47e86b432e130e467a36f4a17 - Patch
References () https://huntr.com/bounties/e79f7774-10fe-46b2-b522-e73b748e3b2d - () https://huntr.com/bounties/e79f7774-10fe-46b2-b522-e73b748e3b2d - Exploit, Third Party Advisory
First Time Lfprojects
Lfprojects mlflow
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-27 15:36


NVD link : CVE-2025-1474

Mitre link : CVE-2025-1474


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-521

Weak Password Requirements