Plaintext Password Storage Vulnerability in ClearML by Allegro AI
CVE-2024-24595
6MEDIUM
What is CVE-2024-24595?
A critical security flaw in Allegro AI's ClearML open-source framework allows for the storage of user passwords in plaintext within the MongoDB instance. This vulnerability poses a significant risk to server integrity, potentially leading to unauthorized access and exposure of sensitive user information. The flaw can result in the leakage of all user emails and passwords, compromising the privacy and security of individuals relying on this machine learning operations solution.
Affected Version(s)
ClearML 0