A vulnerability has been reported in MLflow that could allow an unauthenticated attacker to conduct Server-Side Request Forgery (SSRF) attacks and gain sensitive information on the targeted server.
Target Audience:
All organisations and individuals using affected MLflow.
Risk Assessment:
High risk of compromise of the cloud or enterprise environment.
Impact Assessment:
Potential for unauthorized access to internal services, exfiltrate sensitive metadata/credentials, and conduct internal reconnaissance.
The information provided herein is on "as is" basis, without warranty of any kind.