CRITICAL🇵🇱 Wersja polska

CVE-2024-24593

CVSS 9.6v3.1pub. 2024-02-06upd. 2024-11-21

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.

🤖 AI Analysis
How it works

An attacker prepares a maliciously crafted HTML page that sends requests to the ClearML API in the background using the session of an authenticated user visiting that page. The API server does not properly verify whether the request comes from a trusted source, so it accepts operations initiated by a third party as legitimate actions of the victim. In this way, the attacker can perform API operations with the privileges of the attacked user.

Impact

An attacker can gain unauthorized access to sensitive workspaces and files, steal sensitive information, and attack ClearML platform instances operating in closed internal networks.

Mitigation & patch

The ClearML platform api server component should be updated to a version higher than 1.14.1. Detailed information about available patches should be verified according to the manufacturer's references and HiddenLayer's publication.

Who is affected

All versions of the ClearML (Allegro AI) api server component up to and including version 1.14.1.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Clear Clearml

    APP
    Clear
    ≤ 1.14.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-24592CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w komponencie fileserver platformy ClearML

CVE-2024-24594CRITICAL9.9PL ✓same product

XSS w ClearML — wykonanie JavaScript przez zakładkę Debug Samples

CVE-2024-24590HIGH8.0same product

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s Cle...

CVE-2024-24591HIGH8.0same product

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform ...

CVE-2024-24595MEDIUM6.0same product

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulti...