CVE-2024-6838
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 400
Summary
CVE-2024-6838 is a vulnerability affecting mlflow/mlflow version 2.13.2. This issue allows for the creation or renaming of experiments with unusually long names consisting of a large number of integers. Consequently, the MLflow UI panel may become unresponsive, potentially resulting in a denial of service. Furthermore, there is no character limit for the `artifact_location` parameter when creating an experiment, adding to the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- LF Projects, LLC