CVE-2024-45393 - CVE House
Back to Database
Status published Medium CVE-2024-45393

Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries

Vulnerability Description

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains information about the event that caused the delivery, typically including full details about the object on which an action was performed (such as the task for an "update:task" event), and the user who performed the action. In addition, the attacker can redeliver any past delivery of any webhook, and trigger a ping event for any webhook. Upgrade to CVAT 2.18.0 or any later version.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45393

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cvat
Vulnerable Versions:
>= 2.3.0, < 2.18.0

Timeline

Official Publish: September 10th, 2024
Last Modified: September 10th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Weaknesses (CWE)