CVE-2024-40442: Code Injection
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40442?
CVE-2024-40442 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-40442?
To fix CVE-2024-40442, update Doccano to version 1.8.4 or later and Doccano Auto Labeling Pipeline to version 0.1.23 or later.
Who is affected by CVE-2024-40442?
CVE-2024-40442 affects users of Doccano version 1.8.4 and Doccano Auto Labeling Pipeline version 0.1.23.
What types of attacks are possible with CVE-2024-40442?
CVE-2024-40442 allows remote attackers to escalate privileges through specially crafted REST requests.
Is there a workaround for CVE-2024-40442?
There are no documented workarounds for CVE-2024-40442 aside from applying the available security updates.