CVE-2024-40441: SSRF
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the modelattribs parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40441?
CVE-2024-40441 has a high severity rating due to its potential for privilege escalation by remote attackers.
How do I fix CVE-2024-40441?
To mitigate CVE-2024-40441, upgrade Doccano to version 1.8.5 or later and Doccano Auto Labeling Pipeline to version 0.1.24 or later.
What software is affected by CVE-2024-40441?
CVE-2024-40441 affects Doccano version 1.8.4 and the Doccano Auto Labeling Pipeline version 0.1.23.
Can CVE-2024-40441 be exploited remotely?
Yes, CVE-2024-40441 can be exploited remotely, allowing an attacker to escalate privileges.
What parameter is involved in the CVE-2024-40441 vulnerability?
The vulnerability in CVE-2024-40441 involves the model_attribs parameter for privilege escalation.