PT-2024-20475 · Allegro Ai · Clearml

Published

2024-02-06

·

Updated

2024-02-15

·

CVE-2024-24593

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Allegro AI’s ClearML platform versions prior to 1.14.1
Description A cross-site request forgery (CSRF) vulnerability allows a remote attacker to impersonate a user by sending API requests via maliciously crafted HTML. This can lead to the compromise of confidential workspaces and files, leakage of sensitive information, and targeting of instances of the ClearML platform within closed-off networks.
Recommendations For versions prior to 1.14.1, update to version 1.14.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the API server component to minimize the risk of exploitation. Additionally, be cautious when clicking on links or accessing HTML content from untrusted sources to avoid potential CSRF attacks.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24593

Affected Products

Clearml