A cross-site request forgery (CSRF) vulnerability in all...
Critical severity
Unreviewed
Published
Feb 6, 2024
to the GitHub Advisory Database
•
Updated Feb 6, 2024
Description
Published by the National Vulnerability Database
Feb 6, 2024
Published to the GitHub Advisory Database
Feb 6, 2024
Last updated
Feb 6, 2024
A cross-site request forgery (CSRF) vulnerability in all versions of the api and web server components of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.
References