References https://nvd.nist.gov/vuln/detail/CVE-2024-1483 https://github.com/advisories/GHSA-f82r-jj5r-6g97 https://security.snyk.io/vuln/SNYK-PYTHON-MLFLOW-6615822 https://huntr.com/bounties/52a3855d-93ff-4460-ac24-9c7e4334198d https://vuldb.com/?id.260864 https://www.miggo.io/vulnerability-database/cve/CVE-2024-1483 https://access.redhat.com/security/cve/cve-2024-1483 https://www.resolvedsecurity.com/vulnerability-catalog/CVE-2024-1483
Related VulnerabilitiesPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2026-2614: MLflow <= 3.9.0 - Arbitrary File ReadMLflow 存在任意文件读取漏洞(CVE-2026-2614)金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞vBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)Campcodes Online Loan Management System /ajax.php SQL 注入漏洞(CVE-2025-9744)孚盟云CRM /m/Dingding/Ajax/AjaxProductList.ashx SQL 注入漏洞PoCCVE-2026-2652: MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesPrestaShop ProductsAlert /module/productsalert/AjaxProcess SQL 注入漏洞(CVE-2024-36683)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)孚盟云 CRM /Ajax/upload.ashx DownLoadFieldAttch SQL 注入漏洞