CVE-2023-6778

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clear:clearml_server:*:*:*:*:*:*:*:*

History

08 Feb 2024, 10:15

Type Values Removed Values Added
Summary (en) Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials). (en) Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

22 Dec 2023, 14:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.4
First Time Clear clearml Server
Clear
CPE cpe:2.3:a:clear:clearml_server:*:*:*:*:*:*:*:*
Summary
  • (es) Cross-Site Scripting (XSS) almacenado en el repositorio de GitHub allegroai/clearml-server anterior a 1.13.0. Esta vulnerabilidad afecta al servidor de código abierto ClearML, que no está diseñado para usarse como un servicio disponible públicamente. Las recomendaciones de seguridad enfatizan que debe colocarse detrás de un firewall o VPN de la empresa. Esta vulnerabilidad solo afecta a los usuarios dentro de la misma organización (es decir, cuando una parte malintencionada ya tiene acceso a la red interna y a las credenciales de inicio de sesión de ClearML de un usuario).
References () https://github.com/allegroai/clearml-server/commit/4684fd5b74af582c894b67a0a06e865c948b763a - () https://github.com/allegroai/clearml-server/commit/4684fd5b74af582c894b67a0a06e865c948b763a - Patch
References () https://huntr.com/bounties/5f3fffac-0358-48e6-a500-81bac13e0e2b - () https://huntr.com/bounties/5f3fffac-0358-48e6-a500-81bac13e0e2b - Exploit, Patch, Third Party Advisory

18 Dec 2023, 16:15

Type Values Removed Values Added
Summary (en) Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. (en) Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials).

18 Dec 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 15:15

Updated : 2024-02-08 10:15


NVD link : CVE-2023-6778

Mitre link : CVE-2023-6778

CVE.ORG link : CVE-2023-6778


JSON object : View

Products Affected

clear

  • clearml_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')