Skip to main content

Vendor archive

clear CVEs

Beta · best-effort

10 CVEs tagged to vendor clear5 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-43779

Published Feb 6, 2025

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39272

Published Feb 6, 2025

A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arb…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24594

Published Feb 6, 2024

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload wh…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24593

Published Feb 6, 2024

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24592

Published Feb 6, 2024

Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24591

Published Feb 6, 2024

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24590

Published Feb 6, 2024

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitr…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24595

Published Feb 5, 2024

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6778

Published Dec 18, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1