MLflow의 SSRF 취약점이 공격자에 의해 클라우드 자격 증명 탈취에 악용되고 있다.
MLflow와 FUXA에서 발견된 두 가지 주요 취약점이 공격자들에 의해 악용되고 있으며, 이들 플랫폼의 보안에 심각한 위협이 되고 있다. watchTowr와 VulnCheck의 독립적인 보고서에 따르면, MLflow의 SSRF 취약점은 클라우드 자격 증명과 비밀을 탈취하는 데 사용되고 있다. 이러한 취약점은 오픈 소스 AI 플랫폼과 산업 자동화를 위한 웹 기반 소프트웨어에 영향을 미치고 있다.
Attackers exploit MLflow's SSRF flaw to steal cloud credentials.
Two critical vulnerabilities affecting MLflow and FUXA are being actively exploited by attackers. Reports from watchTowr and VulnCheck indicate that the SSRF flaw in MLflow can be used to steal cloud credentials and secrets. These vulnerabilities pose a significant threat to the security of open-source AI platforms and industrial automation software.