A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.
An attacker prepares a maliciously crafted HTML page that sends requests to the ClearML API in the background using the session of an authenticated user visiting that page. The API server does not properly verify whether the request comes from a trusted source, so it accepts operations initiated by a third party as legitimate actions of the victim. In this way, the attacker can perform API operations with the privileges of the attacked user.
An attacker can gain unauthorized access to sensitive workspaces and files, steal sensitive information, and attack ClearML platform instances operating in closed internal networks.
The ClearML platform api server component should be updated to a version higher than 1.14.1. Detailed information about available patches should be verified according to the manufacturer's references and HiddenLayer's publication.
All versions of the ClearML (Allegro AI) api server component up to and including version 1.14.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HClear Clearml
APPClear≤ 1.14.1
Related vulnerabilities
Brak uwierzytelnienia w komponencie fileserver platformy ClearML
XSS w ClearML — wykonanie JavaScript przez zakładkę Debug Samples
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s Cle...
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform ...
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulti...