Impact
A worker‑role user in CVAT can guess task‑based request identifiers and use the lambda retrieve and destroy endpoints to view annotation requests for tasks or jobs that the user is not authorized to access, as well as to cancel requests initiated by other users. This flaw allows privileged users to read sensitive workflow data and to disrupt other users’ annotation efforts, representing a breach of confidentiality and a potential denial‑of‑service.
Affected Systems
The open‑source video and image annotation platform CVAT, managed by the vendor cvat‑ai, was affected in all releases from 2.17.0 through 2.72.0. The issue was remedied in release 2.72.0 and later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting a low likelihood of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require network access to the CVAT instance and possession of a Worker role account, which typically is granted by an administrator. The attack path involves predicting request IDs and issuing HTTP calls to the protected endpoints.
OpenCVE Enrichment