Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
https://github.com/honysyang/Xinference/tree/main/Xinference_Web
https://github.com/honysyang/Xinference/blob/main/Xinference_Web/Xinference_Web_EN.docx