Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVAT: Flawed authorization logic in endpoints related to lambda requests
Vulnerability Description
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests for tasks or jobs the user cannot access and cancel requests initiated by other users. This issue is fixed in version 2.72.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
cvat.ai CVAT 授权问题漏洞
Vulnerability Description
cvat.ai CVAT是cvat.ai组织开源的一款计算机视觉标注工具。 cvat.ai CVAT 2.17.0版本至2.72.0之前版本存在授权问题漏洞,该漏洞源于授权验证不当,可能导致具有Worker角色的用户使用可预测的基于任务的请求ID访问无权访问的任务或作业的自动注释请求,并取消其他用户发起的请求。
CVSS Information
N/A
Vulnerability Type
N/A