Passwordless User Account Creation in MLflow by Databricks
CVE-2025-1474

5.5MEDIUM

Key Information:

Vendor
Mlflow
Vendor
CVE Published:
20 March 2025

Summary

In MLflow version 2.18, an administrative flaw allows the creation of user accounts without password protection, opening pathways for unauthorized access and undermining established user account management best practices. This vulnerability highlights significant security concerns, as accounts lacking secure credentials can be easily compromised. The issue has been resolved in version 2.19.0, which enforces proper password requirements upon new user account creation.

Affected Version(s)

mlflow/mlflow < 2.19.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.