PT-2024-32381 · Unknown · Computer Vision Annotation Tool

Speclad

·

Published

2024-09-30

·

Updated

2024-10-30

·

CVE-2024-47063

CVSS v4.0

6.2

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Computer Vision Annotation Tool (CVAT) versions prior to 2.19.0
Description The Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. A malicious CVAT user with permissions to create or edit a task can trick another logged-in user into visiting a maliciously-constructed URL, allowing the attacker to initiate API calls on the victim's behalf and gain temporary access to the victim's data.
Recommendations Upgrade to CVAT 2.19.0 or a later version to fix this issue. As a temporary workaround, consider restricting access to sensitive data and API endpoints to minimize the risk of exploitation. Avoid using maliciously-constructed URLs and be cautious when visiting links from untrusted sources.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-47063
GHSA-2C85-39CC-2PX9

Affected Products

Computer Vision Annotation Tool