CVE-2024-47064: Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the victim user has access to. Upgrade to CVAT 2.19.0 or a later version to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47064?
CVE-2024-47064 has been categorized with a severity that indicates a significant risk due to its potential for remote exploitation.
How do I fix CVE-2024-47064?
To fix CVE-2024-47064, you should upgrade CVAT to a version that is not within the vulnerable range, specifically beyond version 2.19.0.
What impact does CVE-2024-47064 have on CVAT users?
CVE-2024-47064 allows attackers to execute API calls on behalf of logged-in CVAT users through crafted URLs, compromising user accounts.
Which versions of CVAT are affected by CVE-2024-47064?
CVE-2024-47064 affects CVAT versions from 2.16.0 up to but not including 2.19.0.
Can CVE-2024-47064 be exploited without user interaction?
CVE-2024-47064 requires an attacker to trick a logged-in user into clicking a malicious link, meaning user interaction is necessary for exploitation.