Incorrect authorization in Computer Vision Annotation Tool (CVAT) - CVE-2024-47172
Published: October 2, 2024
Vulnerability identifier: #VU97950
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47172
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to broken access control in several PATCH endpoints. A remote user can gain access to sensitive information or alter the default source and target storage associated with any project or task.
Affected software
Computer Vision Annotation Tool (CVAT)
How to mitigate CVE-2024-47172
Install updates from vendor's website.
Computer Vision Annotation Tool (CVAT) - update to 2.19.1