CSRF Vulnerability in CVAT Allows Unauthorized API Access
CVAT, a tool for video and image annotation in computer vision, has a security flaw. If a logged-in user visits a harmful URL, an attacker can make API calls with the user's permissions. This means the attacker can see all the data the user can access. Updating to CVAT 2.19.0 or newer versions will fix this problem.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cvat computer vision annotation tool |