Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7jvh-4mqp-gf66

Опубликовано: 23 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.

EPSS

Процентиль: 70%
0.0063
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.6
nvd
больше 1 года назад

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.

EPSS

Процентиль: 70%
0.0063
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-918