Description
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0107 | Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced. |
Github GHSA |
GHSA-f475-x83m-rx5m | Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T18:46:40.834Z
Reserved: 2023-09-22T14:51:42.339Z
Link: CVE-2023-43791
Updated: 2024-08-02T19:52:11.411Z
Status : Modified
Published: 2023-11-09T15:15:08.743
Modified: 2024-11-21T08:24:47.447
Link: CVE-2023-43791
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA