Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43791

Опубликовано: 09 нояб. 2023
Источник: nvd
CVSS3: 9.8
CVSS3: 8.8
EPSS Низкий

Описание

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before 1.8.2, where a patch was introduced.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:humansignal:label_studio:*:*:*:*:*:*:*:*
Версия до 1.8.2 (исключая)

EPSS

Процентиль: 74%
0.00824
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
debian
около 2 лет назад

Label Studio is a multi-type data labeling and annotation tool with st ...

CVSS3: 9.8
github
около 2 лет назад

Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens

EPSS

Процентиль: 74%
0.00824
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-200