Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Security Vulnerability #7884

Open
DanMcInerney opened this issue Feb 22, 2023 · 8 comments
Open

[BUG] Security Vulnerability #7884

DanMcInerney opened this issue Feb 22, 2023 · 8 comments

Comments

@DanMcInerney
Copy link

Sent email to mlflow-oss-maintainers@databricks.com

@BenWilson2
Copy link
Member

Thank you for the investigation and report @DanMcInerney . We'll be patching this!

@mlflow-automation
Copy link
Collaborator

@BenWilson2 @dbczumar @harupy @WeichenXu123 Please assign a maintainer and start triaging this issue.

@badarahmed
Copy link

badarahmed commented Mar 3, 2023

Thanks @DanMcInerney for finding these vulnerabilities along with contributors at @protectai for testing/verification. Appreciate the MLflow maintainers for a very prompt response.

@badarahmed
Copy link

CVEs have been published:

Dan has published blog post detailing the issue at:
https://protectai.com/blog/hacking-ai-system-takeover-exploit-in-mlflow

MLflow v2.2.2 has patched these vulnerabilities.

@yaxxie
Copy link

yaxxie commented Mar 29, 2023

Will the fixes get back ported to the 1.3 series?

@ddl-ebrown
Copy link

Could someone please update the release notes to include mention of the CVEs? I don't know if / where announcements are sent out for this project, but a 10 is typically justification for broad disclosure and an urge to upgrade immediately.

@badarahmed
Copy link

MLflow has issued GitHub Security Advisories:

Disclaimer: I'm not an MLflow maintainer.

@dbczumar
Copy link
Collaborator

dbczumar commented Apr 6, 2023

Hi folks, the 2.2.1 release notes have been updated to reference the GitHub Security Advisories, which refer to the CVEs and provide additional context. The mlflow-users group and Slack channel were contacted as soon as the security advisories were disclosed.

MLflow 1.30.1 was released yesterday, which patches these security vulnerabilities for the 1.30 series: https://pypi.org/project/mlflow/1.30.1/.

Thank you for using MLflow!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants