Show filters
87 Total Results
Displaying 1-10 of 87
Sort by:
Attacker Value
Unknown

CVE-2024-43779

Disclosure Date: February 06, 2025 (last updated February 07, 2025)
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-39272

Disclosure Date: February 06, 2025 (last updated February 07, 2025)
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-24594

Disclosure Date: February 06, 2024 (last updated February 16, 2024)
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.
Attacker Value
Unknown

CVE-2024-24593

Disclosure Date: February 06, 2024 (last updated February 16, 2024)
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.
Attacker Value
Unknown

CVE-2024-24592

Disclosure Date: February 06, 2024 (last updated February 16, 2024)
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
Attacker Value
Unknown

CVE-2024-24591

Disclosure Date: February 06, 2024 (last updated February 16, 2024)
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.
Attacker Value
Unknown

CVE-2024-24590

Disclosure Date: February 06, 2024 (last updated February 16, 2024)
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
Attacker Value
Unknown

CVE-2024-24595

Disclosure Date: February 05, 2024 (last updated February 14, 2024)
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
Attacker Value
Unknown

CVE-2023-6778

Disclosure Date: December 18, 2023 (last updated February 08, 2024)
Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.
Attacker Value
Unknown

CVE-2022-45224

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.