References https://nvd.nist.gov/vuln/detail/CVE-2023-6977 https://huntr.com/bounties/fe53bf71-3687-4711-90df-c26172880aaf https://github.com/advisories/GHSA-qg8p-32gr-gh6x https://www.miggo.io/vulnerability-database/cve/CVE-2023-6977 https://advisories.gitlab.com/pypi/mlflow/CVE-2023-6977/ https://security.snyk.io/vuln/SNYK-PYTHON-MLFLOW-6134596 https://github.com/charlesgargasson/CVE-2023-1177 https://vuldb.com/vuln/248495 https://avd.aliyun.com/product?prod=mlflow https://www.anquan114.com/archives/1140
Related VulnerabilitiesPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2026-2614: MLflow <= 3.9.0 - Arbitrary File ReadMLflow 存在任意文件读取漏洞(CVE-2026-2614)金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞vBulletin /ajax/render/pagenav 代码执行漏洞(CVE-2026-61511)Campcodes Online Loan Management System /ajax.php SQL 注入漏洞(CVE-2025-9744)孚盟云CRM /m/Dingding/Ajax/AjaxProductList.ashx SQL 注入漏洞PoCCVE-2026-2652: MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesPrestaShop ProductsAlert /module/productsalert/AjaxProcess SQL 注入漏洞(CVE-2024-36683)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)孚盟云 CRM /Ajax/upload.ashx DownLoadFieldAttch SQL 注入漏洞