PT-2024-20475 · Allegro Ai · Clearml
Published
2024-02-06
·
Updated
2024-02-15
·
CVE-2024-24593
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Allegro AI’s ClearML platform versions prior to 1.14.1
Description
A cross-site request forgery (CSRF) vulnerability allows a remote attacker to impersonate a user by sending API requests via maliciously crafted HTML. This can lead to the compromise of confidential workspaces and files, leakage of sensitive information, and targeting of instances of the ClearML platform within closed-off networks.
Recommendations
For versions prior to 1.14.1, update to version 1.14.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the API server component to minimize the risk of exploitation. Additionally, be cautious when clicking on links or accessing HTML content from untrusted sources to avoid potential CSRF attacks.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearml