CVE-2023-43791

CVSS V2 None CVSS V3 None
Description
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.
Overview
  • CVE ID
  • CVE-2023-43791
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-11-09T14:42:40.750Z
  • Last Modified Date
  • 2023-11-09T14:42:40.750Z
History
Created Old Value New Value Data Type Notes
2024-06-25 15:46:30 Added to TrackCVE