Unauthorized Data Access and Alteration in CVAT Instances
Computer Vision Annotation Tool (CVAT) helps with annotating videos and images for computer vision. A CVAT account holder can get certain details about any project, task, job, or membership resource on the CVAT platform. The disclosed information is similar to what a GET request returns for that resource. Moreover, the attacker can also change the default source and target storage for any project or task. To address this problem, update to CVAT 2.19.1 or a newer version.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cvat computer vision annotation tool |