Back to the feed

~/article/mlflow-server-side-request-forgery-vulnerability-fkqzi3
criticalSource: CISA

MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Read at the source

Summary written for cymesh.dev. The full article lives at CISA.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/mlflow-server-side-request-forgery-vulnerability-fkqzi3