Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
CVE-2023-43791
9.8CRITICAL
What is CVE-2023-43791?
An identified vulnerability in Label Studio allows attackers to exploit weaknesses within the ORM Leak, enabling them to impersonate any user account. By targeting this flaw, a low privilege user could escalate their access to that of a Django Super Administrator, compromising system integrity. The affected versions are those prior to 1.8.2, which has been patched to prevent such exploits. For more details, refer to HumanSignal's advisory and the relevant patches.
Affected Version(s)
label-studio <= 1.8.1
