GPU VulnDB

Database/AI/ML frameworks & serving

MLflow: basic-auth app leaves tracing and assessment endpoints without permission checks

CVSS 7.1CVE-2025-15381AI/ML frameworks & servingcurated

Impact

When MLflow runs as mlflow server --app-name=basic-auth, the tracing and assessment endpoints are not wired to the permission validators that guard the rest of the API. Any authenticated user - including one holding NO_PERMISSIONS on the experiment - can read trace information for experiments they were never granted and create assessments against those traces. On a shared GPU cluster where MLflow is the common tracking server across teams, that exposes other tenants' trace metadata (prompts, run structure, model and dataset identifiers depending on what is logged) and lets an unprivileged account write misleading evaluation records into someone else's experiment. The vendor scores it confidentiality-low, integrity-high. Deployments not using the basic-auth app are not affected by this path.

Who can reach it

Any user with valid credentials on the MLflow basic-auth app, regardless of their experiment permissions. Network reach to the tracking server plus any account is enough.

What to do

The record does not name a fixed MLflow version - track the huntr report and the Red Hat VEX entry (MLflow is shipped in OpenShift AI) for the fix, then upgrade and restart the tracking server. Until a fixed build is available, treat every account on a basic-auth MLflow instance as able to read all traces: put the server behind an external authorizing proxy, or split teams across separate tracking servers rather than relying on in-app experiment permissions.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.