CVE-2024-47063

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 30, 2024
Updated: Oct 30, 2024
CWE ID 79

Summary

CVE-2024-47063 is a vulnerability affecting Computer Vision Annotation Tool (CVAT). Malicious users with permission to create or edit tasks can manipulate URLs to trick other logged-in users into visiting them. This allows the attacker to initiate API calls on behalf of the victim, granting temporary access to all data the victim user has access to. Address this risk by upgrading to CVAT version 2.19.0 or a later release.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share