MLflow
aidefend-sf0029
MLflow Unauthenticated Webhook Redirect to Full-Read SSRF
- AI Infrastructure
- Credential & Identity Theft
- Data Exfiltration
On a default MLflow Tracking Server through 3.13.0, unauthenticated webhook APIs accept a public HTTPS URL. Delivery follows a 302 without revalidating or pinning the redirect target, and the synchronous test endpoint returns the internal response body.
Mapped threat techniques
AML.T0049Exploit Public-Facing ApplicationAML.T0107Exploitation for Defense EvasionAML.T0025Exfiltration via Cyber Means