MLflow Vulnerability Exploited for Cloud Credential Theft

Researchers have found a critical-severity vulnerability in the open-source MLflow project that allows attackers to steal cloud credentials.

The vulnerability, assigned the CVE ID CVE-2023-2038, has a CVSS score of 9.5. It affects versions 1.13.0 to 1.17.0 of the MLflow project. The attackers exploited the flaw by sending HTTP requests to internal endpoints and extracting sensitive information, including AWS access keys. A proof-of-concept exploit was demonstrated by researchers from Cyberark, who used the vulnerability to gain access to an AWS account. The vulnerability was discovered by researchers from Cyberark, who were testing the MLflow project's security features. The exploit is possible because of the MLflow project's lack of proper input validation, which allows attackers to send malicious HTTP requests. The vulnerability was disclosed publicly by Cyberark on February 10, 2023, and a fix is expected to be released soon. The affected users are advised to update to version 1.18.0 or later.

Source: SecurityWeek