PT-2024-13408 · Unknown · Label Studio

Alex-Elttam

+1

·

Published

2024-01-31

·

Updated

2024-02-09

·

CVE-2023-47116

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Label Studio versions prior to 1.11.0
Description The issue affects Label Studio's SSRF protections, which can be bypassed to access internal web servers. This is because the current SSRF validation is done by executing a single DNS lookup to verify that the IP address is not in an excluded subnet range. This protection can be bypassed by either using HTTP redirection or performing a DNS rebinding attack. The vulnerability poses a significant risk in cloud environments, as it can be used to access internal web servers and partially compromise the confidentiality of those internal servers.
Recommendations For versions prior to 1.11.0, update to version 1.11.0 or later to resolve the issue. As a temporary workaround, consider validating the destination IP address before sending the request to ensure it is not in the deny list. Restrict access to internal cloud API IP ranges to minimize the risk of compromising cloud credentials.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47116
GHSA-P59W-9GQW-WJ8R
PYSEC-2024-127

Affected Products

Label Studio