Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nomadooo

#21232of 53,630
11.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-32382
6.3
2024-09-30
Unknown · Computer Vision Annotation Tool · CVE-2024-47064
**Name of the Vulnerable Software and Affected Versions** Computer Vision Annotation Tool (CVAT) versions prior to 2.19.0 **Description** The issue allows an attacker to initiate API calls on behalf of a logged-in user if they can trick the user into visiting a maliciously-constructed URL. This gives the attacker temporary access to all data that the victim user has access to. **Recommendations** Upgrade to CVAT 2.19.0 or a later version to fix this issue.
PT-2024-32456
5.4
2024-09-30
Cvat · Cvat · CVE-2024-47172
**Name of the Vulnerable Software and Affected Versions** Computer Vision Annotation Tool (CVAT) versions prior to 2.19.1 **Description** The issue allows an attacker with a CVAT account to retrieve certain information about any project, task, job, or membership resource on the CVAT instance. This information is the same as the information returned on a GET request to the resource. Additionally, the attacker can alter the default source and target storage associated with any project or task. **Recommendations** Upgrade to CVAT 2.19.1 or any later version to fix the issue.