References https://nvd.nist.gov/vuln/detail/CVE-2024-3848 https://github.com/advisories/GHSA-rfqq-wq6w-72jm https://security.snyk.io/vuln/SNYK-PYTHON-MLFLOW-6860431 https://huntr.com/bounties/8d5aadaa-522f-4839-b41b-d7da362dd610 https://github.com/mlflow/mlflow/commit/f8d51e21523238280ebcfdb378612afd7844eca8 https://access.redhat.com/security/cve/CVE-2024-3848
Related VulnerabilitiesPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2026-2614: MLflow <= 3.9.0 - Arbitrary File ReadMLflow 存在任意文件读取漏洞(CVE-2026-2614)金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞vBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)Campcodes Online Loan Management System /ajax.php SQL 注入漏洞(CVE-2025-9744)孚盟云CRM /m/Dingding/Ajax/AjaxProductList.ashx SQL 注入漏洞PoCCVE-2026-2652: MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesPrestaShop ProductsAlert /module/productsalert/AjaxProcess SQL 注入漏洞(CVE-2024-36683)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)孚盟云 CRM /Ajax/upload.ashx DownLoadFieldAttch SQL 注入漏洞