Privilege Escalation Vulnerability in Doccano Annotation Tools
CVE-2024-40441

6.6MEDIUM

Key Information:

Vendor

Doccano

Vendor
CVE Published:
23 September 2024

What is CVE-2024-40441?

A vulnerability in the Doccano Open Source Annotation Tools for machine learning practitioners and its Auto Labeling Pipeline module allows remote attackers to escalate their privileges through manipulation of the model_attribs parameter. This can lead to unauthorized access and control over the application, making it crucial for users to secure their deployments by applying necessary patches provided in the latest releases.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.