Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
CVE-2023-43791

9.8CRITICAL

Key Information:

Vendor
CVE Published:
9 November 2023

What is CVE-2023-43791?

An identified vulnerability in Label Studio allows attackers to exploit weaknesses within the ORM Leak, enabling them to impersonate any user account. By targeting this flaw, a low privilege user could escalate their access to that of a Django Super Administrator, compromising system integrity. The affected versions are those prior to 1.8.2, which has been patched to prevent such exploits. For more details, refer to HumanSignal's advisory and the relevant patches.

Affected Version(s)

label-studio <= 1.8.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.