Object Relational Mapper Leak Vulnerability in Filtering Task in Label Studio
CVE-2023-47117

7.5HIGH

Key Information:

Vendor
CVE Published:
13 November 2023

What is CVE-2023-47117?

Label Studio, an open source data labeling tool, is vulnerable due to the insecure handling of filters used for task management. This creates an opportunity for attackers to construct malicious filter chains, allowing them to access sensitive information across user accounts. By exploiting the Django Object Relational Mapper (ORM), an attacker can manipulate filter results, leading to the gradual leakage of sensitive fields. Further compounding the issue, a hard-coded secret key within Label Studio can be exploited to forge session tokens, potentially allowing unauthorized access to user accounts. This serious vulnerability affects all versions prior to 1.9.2post0, which has since been patched. Users must upgrade immediately as there are no viable workarounds.

Affected Version(s)

label-studio < 1.9.2post0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.