PT-2024-28849 · Unknown+1 · Doccano Auto Labeling Pipeline+1

Gian2Dchris

·

Published

2024-09-23

·

Updated

2024-09-26

·

CVE-2024-40442

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Doccano Open source annotation tools for machine learning practitioners version 1.8.4 Doccano Auto Labeling Pipeline module version 0.1.23
Description An issue in the affected software allows a remote attacker to escalate privileges via a crafted REST Request. This issue affects the ability to annotate documents automatically and may lead to unauthorized access.
Recommendations For Doccano Open source annotation tools for machine learning practitioners version 1.8.4, consider disabling the REST API endpoint until a patch is available. For Doccano Auto Labeling Pipeline module version 0.1.23, restrict access to the automatic annotation feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-40442

Affected Products

Doccano
Doccano Auto Labeling Pipeline