PT-2025-5837 · Unknown · Clearml Enterprise Server

Edwin Molenaar

·

Published

2025-02-06

·

Updated

2025-09-05

·

CVE-2024-43779

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ClearML Enterprise Server version 3.22.5-1533
Description: An information disclosure issue exists in the Vault API functionality. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this issue.
Recommendations: For ClearML Enterprise Server version 3.22.5-1533, consider disabling the Vault API functionality until a patch is available to prevent potential information disclosure. Restrict access to the Vault API to minimize the risk of exploitation. Avoid using the Vault API for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43779

Affected Products

Clearml Enterprise Server