Plaintext Password Storage Vulnerability in ClearML by Allegro AI
CVE-2024-24595

6MEDIUM

Key Information:

Vendor

Allegro.ai

Status
Vendor
CVE Published:
5 February 2024

What is CVE-2024-24595?

A critical security flaw in Allegro AI's ClearML open-source framework allows for the storage of user passwords in plaintext within the MongoDB instance. This vulnerability poses a significant risk to server integrity, potentially leading to unauthorized access and exposure of sensitive user information. The flaw can result in the leakage of all user emails and passwords, compromising the privacy and security of individuals relying on this machine learning operations solution.

Affected Version(s)

ClearML 0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.