CVE-2024-24593

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:clear:clearml:*:*:*:*:*:*:*:*

History

15 Feb 2024, 16:55

Type Values Removed Values Added
First Time Clear
Clear clearml
References () https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/ - () https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/ - Exploit, Technical Description, Third Party Advisory
CPE cpe:2.3:a:clear:clearml:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 8.8

13 Feb 2024, 20:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de cross-site request forgery (CSRF) en todas las versiones de la API y los componentes del servidor web de la plataforma ClearML de Allegro AI, permite a un atacante remoto hacerse pasar por un usuario enviando solicitudes de API a través de HTML creado con fines malintencionados. La explotación de la vulnerabilidad permite a un atacante comprometer espacios de trabajo y archivos confidenciales, filtrar información confidencial y apuntar a instancias de la plataforma ClearML dentro de redes cerradas.
Summary (en) A cross-site request forgery (CSRF) vulnerability in all versions of the api and web server components of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks. (en) A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.

06 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 15:15

Updated : 2024-02-15 16:55


NVD link : CVE-2024-24593

Mitre link : CVE-2024-24593

CVE.ORG link : CVE-2024-24593


JSON object : View

Products Affected

clear

  • clearml
CWE
CWE-352

Cross-Site Request Forgery (CSRF)