CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-20 10:15

Updated : 2025-03-27 15:36


NVD link : CVE-2025-1474

Mitre link : CVE-2025-1474

CVE.ORG link : CVE-2025-1474


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-521

Weak Password Requirements