mlflow-oidc-auth is vulnerable to Improper Authentication
82
High Risk
The plugin validates OIDC bearer tokens against any provider in its multi-provider registry but keys the resulting identity on the username claim alone, without binding it to the provider that asserted it. A valid token from one configured provider whose username claim matches an account owned by a different provider is authenticated as that account, allowing cross-provider account takeover. When bearer group claims are trusted, a secondary provider whose token asserts a group named like the admin group also provisions the principal as an administrator, because no policy limits which providers may confer administrator rights. The fix binds identities to the asserting provider and adds a per-provider admin_source policy so only trusted providers can grant admin.
You are affected if you are using a version that falls within the vulnerable range and your deployment configures more than one identity provider in the OIDC provider registry.
mlflow-oidc-auth is vulnerable to Improper Authentication in versions 7.15.0 - 7.16.0.
Upgrade the mlflow-oidc-auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.