MLflow SSRF Flaw Exploited for Cloud Credential Theft
Attackers are exploiting critical MLflow and FUXA vulnerabilities to steal cloud credentials and execute code.
13 results for “ssrf”
Attackers are exploiting critical MLflow and FUXA vulnerabilities to steal cloud credentials and execute code.
A critical server-side request forgery vulnerability in Microsoft Office SharePoint allows unauthorized network spoofing and carries a CVSS score of 9.6.
A critical server-side request forgery vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve privilege escalation.
A critical vulnerability in the Flyto-Core verification service allows unauthenticated attackers to steal internal secrets and perform SSRF attacks.
A critical vulnerability in the vault-secrets-webhook allows unauthorized outbound requests and potential theft of cluster-wide service account tokens.
A critical server-side request forgery vulnerability in IBM WebSphere Application Server allows unauthenticated attackers to potentially compromise systems.
A critical vulnerability in OpenDJ allows unauthenticated attackers to perform SSRF, read local files, and trigger memory-exhaustion denial-of-service attacks.
A critical vulnerability in Budibase allows unauthenticated attackers to steal stored REST datasource credentials via a cross-origin request leak.
A critical Server-Side Request Forgery vulnerability in Data Quality has been identified, carrying a maximum CVSS 3.1 severity score.
A critical vulnerability in the lmdeploy API server enables unauthenticated attackers to reach internal network services.
A critical server-side request forgery vulnerability in stoatchat allows unauthenticated attackers to access internal network infrastructure.
A critical server-side request forgery vulnerability in Stoatchat versions prior to 0.13.5 allows unauthenticated access to networks.
Critical SSRF and code injection flaws in SMA1000 appliances are currently being exploited, prompting an urgent patching mandate.