EXPOSURE MLflow
SEVERITY HIGH
PROBE GET :5000/version
Is your MLflow exposed?
Tracking UI/API reachable: experiments, artifact paths, and often logged credentials on display.
Scan a host you own → Fix card
Why it matters
An open MLflow server lets strangers list experiments, read artifact paths, and often pull logged models or credentials stored as params.
How common is it?
A published population estimate for MLflow is still collecting. See the census methodology.
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: