Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
clear clearml server vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-6778
Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server before 1.13.0.
Clear Clearml Server
7.1
CVSSv3
CVE-2024-24595
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
Clear Clearml -
5.4
CVSSv3
CVE-2024-24594
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote malicious user to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.
Clear Clearml -
8.8
CVSSv3
CVE-2024-24593
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote malicious user to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnera...
Clear Clearml
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started