Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains information about the event that caused the delivery, typically including full details about the object on which an action was performed (such as the task for an "update:task" event), and the user who performed the action. In addition, the attacker can redeliver any past delivery of any webhook, and trigger a ping event for any webhook. Upgrade to CVAT 2.18.0 or any later version.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains information about the event that caused the delivery, typically including full details about the object on which an action was performed (such as the task for an "update:task" event), and the user who performed the action. In addition, the attacker can redeliver any past delivery of any webhook, and trigger a ping event for any webhook. Upgrade to CVAT 2.18.0 or any later version. | |
Title | Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-10T15:04:13.556Z
Updated: 2024-09-10T19:25:11.113Z
Reserved: 2024-08-28T20:21:32.802Z
Link: CVE-2024-45393
Vulnrichment
Updated: 2024-09-10T19:24:51.402Z
NVD
Status : Awaiting Analysis
Published: 2024-09-10T15:15:18.657
Modified: 2024-09-10T15:50:47.237
Link: CVE-2024-45393
Redhat
No data.