References https://nvd.nist.gov/vuln/detail/cve-2023-3765 https://github.com/advisories/GHSA-fmxj-6h9g-6vw3 https://www.ddpoc.com/DVB-2023-4778.html https://qkl.seebug.org/vuldb/ssvid-99739 https://cn-sec.com/archives/1928287.html https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=34441 https://www.sentinelone.com/vulnerability-database/cve-2023-3765/ https://security.snyk.io/vuln/SNYK-PYTHON-MLFLOW-5781352 https://advisories.checkpoint.com/defense/advisories/public/2024/cpai-2023-1449.html/
Related VulnerabilitiesMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2026-2614: MLflow <= 3.9.0 - Arbitrary File ReadMLflow 存在任意文件读取漏洞(CVE-2026-2614)PoCCVE-2026-2652: MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesMLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)PoCCVE-2026-0545: MLflow Job API - Authentication BypassPoCCVE-2023-1177: Mlflow <2.2.1 - Local File InclusionPoCCVE-2023-2356: Mlflow <2.3.0 - Local File InclusionPoCCVE-2023-2780: Mlflow <2.3.1 - Local File Inclusion BypassPoCCVE-2023-3765: MLflow Absolute Path TraversalPoCCVE-2023-43472: MLFlow < 2.8.1 - Sensitive Information DisclosurePoCCVE-2023-6018: Mlflow - Arbitrary File Write