PT-2022-23461 · Heartex · Label Studio Community Edition

Guilhermemachado26

·

Published

2022-10-03

·

Updated

2023-03-28

·

CVE-2022-36551

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Heartex - Label Studio Community Edition versions 1.5.0 and earlier
Description A Server Side Request Forgery (SSRF) in the Data Import module allows an authenticated user to access arbitrary files on the system. Self-registration is enabled by default, enabling a remote attacker to create a new account and then exploit the SSRF.
Recommendations For versions 1.5.0 and earlier, update to version 1.6.0 to resolve the issue. As a temporary workaround, consider disabling the self-registration feature and restricting access to the Data Import module to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36551
GHSA-PC6F-259W-W3J6
PYSEC-2022-300

Affected Products

Label Studio Community Edition