Vulnerability Details CVE-2025-1473
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.0%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-1473
-
cpe:2.3:a:lfprojects:mlflow:2.17.0
-
cpe:2.3:a:lfprojects:mlflow:2.17.1
-
cpe:2.3:a:lfprojects:mlflow:2.17.2
-
cpe:2.3:a:lfprojects:mlflow:2.18.0
-
cpe:2.3:a:lfprojects:mlflow:2.19.0
-
cpe:2.3:a:lfprojects:mlflow:2.20.0