CVE-2025-1474 - Apache MLflow Passwordless User Account Creation Vulnerability
CVE ID : CVE-2025-1474
Published : March 20, 2025, 10:15 a.m. | 2 hours ago
Description : In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 20, 2025, 10:15 a.m. | 2 hours ago
Description : In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...