Skip to content

SSRF Vulnerability in CVAT

High
nmanovic published GHSA-69qq-p6vh-xjqj Aug 22, 2022

Package

CVAT (server)

Affected versions

<= 1.7.0

Patched versions

2.0.0

Description

Impact

What kind of vulnerability is it? Who is impacted?

Server-side request forgery (SSRF)

Patches

Has the problem been patched? What versions should users upgrade to?

It was fixed in v2.0.0 released on 2022-03-04.
Added validation for URLs which used as remote data source (6fad176).

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

N/A

References

Are there any links users can visit to find out more?

Server-side request forgery (SSRF)

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-31188

Weaknesses

No CWEs

Credits