CyberRota
← Ana sayfaya dön

CVE-2026-3198

MEDIUM · CVSS 6.5 EPSS %0.24

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-02T04:17:03.397 · Çekilme zamanı: 2026-06-30T12:07:35.482282+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-3198
Severity
MEDIUM
CVSS
6.5
EPSS
%0.24

Orijinal NVD Açıklaması

MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`. This allows any authenticated user, regardless of their assigned permissions, to enumerate all gateway secrets, endpoints, and model definitions. This vulnerability exposes sensitive information, such as API keys, endpoint configurations, and proprietary model definitions, to unauthorized users.