PT-2024-20473 · Allegro Ai · Clearml
Published
2024-02-06
·
Updated
2024-02-15
·
CVE-2024-24591
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Allegro AI's ClearML platform versions 1.4.0 through 1.14.1
Description
A path traversal vulnerability in the client SDK of Allegro AI's ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user's system when interacted with.
Recommendations
For versions 1.4.0 through 1.14.1, consider restricting access to the dataset upload feature until a patch is available.
As a temporary workaround, avoid interacting with maliciously uploaded datasets to minimize the risk of exploitation.
Restrict write access to sensitive locations on the end user's system to prevent arbitrary file writing.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearml