Label Studio 未将标注详情接口(annotation detail endpoint)的作用域限制在请求用户所属的组织内。 中的 定义了 ,并且没有提供 的重写方法,因此默认的查询逻辑会通过主键获取任意一条标注记录。该视图所要求的权限( )包括 、 和 ,而 中将所有权限配置为仅要求用户通过身份验证( ),因此任何已登录的用户账户均可通过权限检查,且未执行基于对象级别的组织归属校验。 相比之下,同文件中的 sibling task 接口会将其查询集限制为请求用户当前活跃组织所属的项目(通过 字段),从而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HumanSignal | label-studio | ≤ 1.23.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HumanSignal | label-studio | 0 ~ 1.23.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet