Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-48381

Опубликовано: 30 мая 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs and names of all tasks, projects, labels, and the IDs of all jobs and quality reports on the CVAT instance. In addition, if the instance contains many resources of a particular type, retrieving this information may tie up system resources, denying access to legitimate users. This issue has been patched in version 2.38.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cvat:computer_vision_annotation_tool:*:*:*:*:*:*:*:*
Версия от 2.4.0 (включая) до 2.38.0 (исключая)

EPSS

Процентиль: 13%
0.00043
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201

EPSS

Процентиль: 13%
0.00043
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-201