CVE-2025-1473 Details
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Signup feature of MLflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which could be used to perform unauthorized actions on behalf of the user.
Users can disable CSRF protection by setting the 'MLFLOW_FLASK_SERVER_SECRET_KEY' environment variable to 'None'. However, this may expose the application to other CSRF-related vulnerabilities.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mlflow/mlflow/commit/ecfa61cb43d3303589f3b5834fd95991c9706628 | [email protected] | Patch |
| https://huntr.com/bounties/43dc50b6-7d1e-41b9-9f97-f28809df1d45 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects mlflow | >= 2.17.0, < 2.20.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | Initial Analysis | [email protected] |
| Mar 20, 2025 | New CVE Received | [email protected] |