CVE-2022-36551
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.
Una vulnerabilidad de tipo Server Side Request Forgery (SSRF) en el módulo de importación de datos en Heartex - Label Studio Community Edition versiones 1.5.0 y anteriores, permite a un usuario autenticado acceder a archivos arbitrarios en el sistema. Además, el auto registro está habilitado por defecto en estas versiones de Label Studio, permitiendo a un atacante remoto crear una nueva cuenta y luego explotar una vulnerabilidad de tipo SSRF
Label Studio versions 1.5.0 and below suffer from a server-side request forgery vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-25 CVE Reserved
- 2022-10-03 CVE Published
- 2023-03-28 First Exploit
- 2024-07-22 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://heartex.com | Product | |
http://labelstud.io | Product | |
http://packetstormsecurity.com/files/171548/Label-Studio-1.5.0-Server-Side-Request-Forgery.html |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51109 | 2023-03-28 |
URL | Date | SRC |
---|---|---|
https://github.com/heartexlabs/label-studio/pull/2840 | 2023-03-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Heartex Search vendor "Heartex" | Label Studio Search vendor "Heartex" for product "Label Studio" | <= 1.5.0 Search vendor "Heartex" for product "Label Studio" and version " <= 1.5.0" | community |
Affected
|