Skip to content

[GHSA-gq3w-7jj3-x7gr] MLflow Use of Default Password Authentication Bypass Vulnerability - #9438

Open
tanghaoji wants to merge 1 commit into
tanghaoji/advisory-improvement-9438from
tanghaoji-GHSA-gq3w-7jj3-x7gr
Open

[GHSA-gq3w-7jj3-x7gr] MLflow Use of Default Password Authentication Bypass Vulnerability#9438
tanghaoji wants to merge 1 commit into
tanghaoji/advisory-improvement-9438from
tanghaoji-GHSA-gq3w-7jj3-x7gr

Conversation

@tanghaoji

Copy link
Copy Markdown

Updates

  • Affected products
  • References

Comments
The referenced fix (#19260, commit 5bf2ec2, v3.8.0rc0) addresses an unrelated artifact path-traversal issue. The default admin / password1234 credential in basic_auth.ini remained in every release through 3.16.0. It will be removed in #25751, released in 3.16.1, which ships no default admin password and refuses to bootstrap the admin user without an explicitly configured one.

@github-actions
github-actions Bot changed the base branch from main to tanghaoji/advisory-improvement-9438 September 10, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant