Vulnerabilities > Clear

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-24590 Deserialization of Untrusted Data vulnerability in Clear Clearml
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
network
low complexity
clear CWE-502
8.8
2024-02-06 CVE-2024-24591 Path Traversal vulnerability in Clear Clearml 1.14.1/1.4.0
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.
network
low complexity
clear CWE-22
8.8
2024-02-06 CVE-2024-24592 Improper Authentication vulnerability in Clear Clearml
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
network
low complexity
clear CWE-287
critical
9.8
2024-02-06 CVE-2024-24593 Cross-Site Request Forgery (CSRF) vulnerability in Clear Clearml 0.17.0/1.14.1/1.4.0
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html.
network
low complexity
clear CWE-352
8.8
2024-02-06 CVE-2024-24594 Cross-site Scripting vulnerability in Clear Clearml
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.
network
low complexity
clear CWE-79
5.4
2024-02-05 CVE-2024-24595 Insufficiently Protected Credentials vulnerability in Clear Clearml
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
local
low complexity
clear CWE-522
7.1
2023-12-18 CVE-2023-6778 Cross-site Scripting vulnerability in Clear Clearml Server
Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.
network
low complexity
clear CWE-79
5.4
2010-12-30 CVE-2010-4507 Cross-Site Request Forgery (CSRF) vulnerability in Clear products
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the cmd parameter in an act_cmd_result action to webmain.cgi, (2) enable remote management via an enable_remote_access act_network_set action to webmain.cgi, (3) enable the TELNET service via an ENABLE_TELNET act_set_wimax_etc_config action to webmain.cgi, (4) enable TELNET sessions via a certain act_network_set action to webmain.cgi, or (5) read arbitrary files via the FILE_PATH parameter in an act_file_download action to upgrademain.cgi.
network
clear CWE-352
critical
9.3