PT-2022-23461 · Heartex · Label Studio Community Edition
Guilhermemachado26
·
Published
2022-10-03
·
Updated
2023-03-28
·
CVE-2022-36551
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Heartex - Label Studio Community Edition versions 1.5.0 and earlier
Description
A Server Side Request Forgery (SSRF) in the Data Import module allows an authenticated user to access arbitrary files on the system. Self-registration is enabled by default, enabling a remote attacker to create a new account and then exploit the SSRF.
Recommendations
For versions 1.5.0 and earlier, update to version 1.6.0 to resolve the issue. As a temporary workaround, consider disabling the self-registration feature and restricting access to the Data Import module to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Label Studio Community Edition