PT-2024-31985 · Wandb · Wandb

Published

2024-05-16

·

Updated

2024-05-16

·

CVE-2024-4642

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wandb (affected versions not specified)
Description A Server-Side Request Forgery (SSRF) issue exists due to improper handling of HTTP 302 redirects. This allows team members with access to the 'User settings -> Webhooks' function to exploit the issue and access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4642
GHSA-CQH9-JFQR-H9JJ

Affected Products

Wandb