Lucene search

K
cve6f8de1f0-f67e-45a6-b68f-98777fdb759cCVE-2024-24595
HistoryFeb 05, 2024 - 10:16 p.m.

CVE-2024-24595

2024-02-0522:16:08
CWE-522
6f8de1f0-f67e-45a6-b68f-98777fdb759c
web.nvd.nist.gov
15
allegro ai
clearml
open-source
plaintext passwords
mongodb
server compromise
nvd

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.0%

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

Affected configurations

NVD
Node
clearclearmlMatch-
CPENameOperatorVersion
clear:clearmlclear clearmleq-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "packageName": "clearml-server",
    "product": "ClearML",
    "repo": "https://github.com/allegroai/clearml-server",
    "vendor": "Allegro.AI",
    "versions": [
      {
        "status": "affected",
        "version": "0"
      }
    ]
  }
]

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.0%

Related for CVE-2024-24595