Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0107 Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.
Github GHSA Github GHSA GHSA-f475-x83m-rx5m Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-03T18:46:40.834Z

Reserved: 2023-09-22T14:51:42.339Z

Link: CVE-2023-43791

cve-icon Vulnrichment

Updated: 2024-08-02T19:52:11.411Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T15:15:08.743

Modified: 2024-11-21T08:24:47.447

Link: CVE-2023-43791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses