Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc6f-259w-w3j6

Опубликовано: 04 окт. 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF. This issue is fixed in version 1.6.0.

Пакеты

Наименование

label-studio

pip
Затронутые версииВерсия исправления

< 1.6.0

1.6.0

EPSS

Процентиль: 88%
0.04
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.

EPSS

Процентиль: 88%
0.04
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-918