- CVSS
- HIGH · 7.1v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
- Published
- 2025-03-20
- Weakness
- CWE-352
- Source
- nvd.nist.gov/vuln/detail/CVE-2025-1473
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2025-1473 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.