Environment Variable Exposure in MLflow by Databricks
⚠️ CVE-Referenzen:
CVE-2026-4035
Mlflow - Mlflow/mlflow - CRITICAL - CVE-2026-4035.
A vulnerability exists in MLflow versions prior to 3.11.0 that can lead to the unauthorized disclosure of sensitive server-side environment variables through improperly secured gateway secrets. The issue permits the resolution of `$ENV_VAR` references within the `api_key` field during runtime, allowing attackers to intercept sensitive credentials sent in API authentication headers. This can be exploited by low-privileged authenticated users or even unauthenticated users in certain configurations, potentially leading to serious security ramifications including cloud credential leakage. It's crucial for users to update to version 3.11.0 to mitigate these risks effectively.
Quelle: securityvulnerability.io