pkg:Bitnami/mlflow
67 total CVEsCRITICAL18HIGH38MEDIUM9LOW2
✅ Check your installed version
All known vulnerabilities
- >= 3.8.0, < 3.9.0
- from 0, < 2.9.1
- from 0, < 2.9.2
- from 0, < 2.8.1
- from 0, < 2.5.0
- from 0, < 2.3.1
- from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.3.1
- from 0, < 2.2.1
- >= 3.9.0, < 3.10.0
- from 0, < 3.11.1
- from 0, < 3.9.0
- CRITICAL9.6CVE-2024-27132Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.from 0, < 2.10.0
- CRITICAL9.6CVE-2024-27133Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.from 0, < 2.10.0
- from 0, < 2.10.0
- CRITICAL9.1CVE-2023-6014MLflow authentication requirement bypass can allow a user to arbitrarily create an account
- >= 2.0.0, <= 2.13.1
- >= 1.11.0, < 2.13.2
- >= 1.27.0, < 2.13.2
- >= 0.5.0, < 2.13.2
- >= 2.5.0, < 2.13.2
- >= 0.9.0, < 2.13.2
- >= 1.23.0, < 2.13.2
- >= 1.1.0, < 2.13.2
- >= 1.1.0, < 2.13.2
- >= 1.24.0, < 2.13.2
- from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.9.2
- HIGH8.8CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowfrom 0, < 2.9.2
- from 0, < 2.6.0
- from 0, < 3.10.0
- from 0, < 1.23.1
- from 0, < 3.11.1
- from 0, < 3.5.0
- HIGH8.1CVE-2025-11201MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerabilityfrom 0, < 3.0.0
- from 0, < 2.21.1
- from 0, < 2.12.2
- from 0, < 3.10.0
- from 0, < 3.7.0
- >= 2.15.1, < 2.16.0
- from 0, < 2.11.3
- from 0, < 2.12.1
- from 0, < 2.12.1
- from 0, < 2.11.3
- from 0, < 2.11.3
- from 0, < 2.12.1
- >= 1.0.0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.8.2
- from 0, < 2.0.1
- from 0, < 3.9.0
- from 0, < 3.4.0
- HIGH7.0CVE-2024-27134Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udffrom 0, < 2.16.0
- from 0, < 2.9.1
- >= 2.17.2, < 2.18.0
- from 0, < 3.1.0
- from 0, < 3.11.1
- >= 2.17.0, < 2.20.1
- from 0, < 2.12.1
- >= 2.13.2, < 2.14.0
- from 0, < 3.11.1
- from 0, < 2.19.0
- from 0, < 2.2.2