在 Doccano(面向机器学习从业者的开源标注工具)的自动标注流水线模块(Auto Labeling Pipeline Module)中,发现了一个安全漏洞,受影响版本为 1.8.5 及以下版本。具体受影响的功能位于 路径下“项目示例详情端点”(Project Example Detail Endpoint)中的 函数。该漏洞的成因是访问控制不当,攻击者可通过远程方式发起攻击。目前该漏洞的利用方法已公开,因此可能已被利用。披露方在早期已联系供应商,但供应商未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Doccano | Open Source Annotation Tools for Machine Learning Practitioners | 1.8.0 |
cpe:2.3:a:doccano:open_source_annotation_tools_for_machine_learning_practitioners:*:*:*:*:*:*:*:*
|
|
| Doccano | Auto Labeling Pipeline Module to Annotate a Document Automatically | 1.8.0 |
cpe:2.3:a:doccano:auto_labeling_pipeline_module_to_annotate_a_document_automatically:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet