vendor:
CVAT
by:
Emir Polat
9.8
CVSS
CRITICAL
Server-side request forgery (SSRF)
918
CWE
Product Name: CVAT
Affected Version From: 1.7.2000
Affected Version To: 2.0.0
Patch Exists: YES
Related CWE: CVE-2022-31188
CPE: a:opencv:cvat
Platforms Tested: Ubuntu 20.04.4 LTS (GNU/Linux 5.4.0-122-generic x86_64)
2021
CVAT 2.0 – SSRF (Server Side Request Forgery)
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade.
Mitigation:
Upgrade to version 2.0.0 or later