CVE-2022-27234: SSRF
Published Feb 16, 2023
·Updated
Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable information disclosure via network access.
Affected Software
1 affected component
Intel Computer Vision Annotation Tool<2.0.1
Event History
Feb 16, 2023
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-27234 vulnerability?
CVE-2022-27234 is a server-side request forgery vulnerability in the CVAT software maintained by Intel(R) before version 2.0.1.
2
How does CVE-2022-27234 affect the CVAT software?
CVE-2022-27234 may allow an authenticated user to potentially enable information disclosure via network access.
3
What is the severity of CVE-2022-27234?
CVE-2022-27234 has a severity rating of 6.5 (medium).
4
How can I fix CVE-2022-27234?
To fix CVE-2022-27234, update the CVAT software to version 2.0.1 or later, as provided by Intel(R).
5
Where can I find more information about CVE-2022-27234?
More information about CVE-2022-27234 can be found on Intel's security advisory page: http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00762.html