Description
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected products
- lfprojects / MLflow3.15.0
- mlflow / mlflow< 3.15.0 – < 3.15.0
Exploits & proofs of concept
- nucleiMLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypassby DhiyaneshDk
References
- VENDOR_ADVISORYhttps://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j
- MISChttps://github.com/mlflow/mlflow/issues/24179
- PATCHhttps://github.com/mlflow/mlflow/pull/24258
- PATCHhttps://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939
- PATCHhttps://github.com/mlflow/mlflow/releases/tag/v3.15.0
Updated 6m ago · 8 sources