from Hacker News

Critical remote unauthenticated system/cloud takeover in major AI tool

by DanMcInerney on 3/24/23, 12:26 PM with 2 comments

  • by DanMcInerney on 3/24/23, 2:32 PM

    Pretty brutal. Took me about 3 days to find. I suspect there's more.

    * Unauthenticated

    * Remote

    * No user interaction

    * No prerequisite knowledge or environment setup

    * Large adoption on MLflow in AI engineering workflows

    Here's the GitHub Security Advisory: https://github.com/mlflow/mlflow/security/advisories/GHSA-xg...

  • by carterdea on 3/24/23, 4:26 PM

    Wow, this is a pretty important find. Thanks for the responsible disclosure!