Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
Vulnerability Description
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-43791
Credits & Attribution
No credits recorded in the NVD database.
References
More from HumanSignal
View All →Affected Vendor
HumanSignal
View all reports →