Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the victim user has access to. Upgrade to CVAT 2.19.0 or a later version to fix this issue.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cvat
Cvat computer Vision Annotation Tool |
|
CPEs | cpe:2.3:a:cvat:computer_vision_annotation_tool:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cvat
Cvat computer Vision Annotation Tool |
|
Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cvat-ai
Cvat-ai cvat |
|
CPEs | cpe:2.3:a:cvat-ai:cvat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cvat-ai
Cvat-ai cvat |
|
Metrics |
ssvc
|
Mon, 30 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the victim user has access to. Upgrade to CVAT 2.19.0 or a later version to fix this issue. | |
Title | Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-30T14:45:02.035Z
Updated: 2024-09-30T16:39:39.911Z
Reserved: 2024-09-17T17:42:37.027Z
Link: CVE-2024-47063
Vulnrichment
Updated: 2024-09-30T16:39:32.352Z
NVD
Status : Analyzed
Published: 2024-09-30T15:15:06.293
Modified: 2024-10-30T18:24:21.000
Link: CVE-2024-47063
Redhat
No data.