logo

Database

Excessive privileges In mlflow

Description

MLflow's excessive directory permissions allow local privilege escalation Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-23AG8 – Vulnerability | Fluid Attacks Database