PT-2024-32381 · Unknown · Computer Vision Annotation Tool
Speclad
·
Published
2024-09-30
·
Updated
2024-10-30
·
CVE-2024-47063
CVSS v4.0
6.2
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Computer Vision Annotation Tool (CVAT) versions prior to 2.19.0
Description
The Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. A malicious CVAT user with permissions to create or edit a task can trick another logged-in user into visiting a maliciously-constructed URL, allowing the attacker to initiate API calls on the victim's behalf and gain temporary access to the victim's data.
Recommendations
Upgrade to CVAT 2.19.0 or a later version to fix this issue. As a temporary workaround, consider restricting access to sensitive data and API endpoints to minimize the risk of exploitation. Avoid using maliciously-constructed URLs and be cautious when visiting links from untrusted sources.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Computer Vision Annotation Tool