Vulnerability Description
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clear | Clearml | - |
Related Weaknesses (CWE)
References
- https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-Third Party Advisory
- https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-Third Party Advisory
FAQ
What is CVE-2024-24595?
CVE-2024-24595 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
How severe is CVE-2024-24595?
CVE-2024-24595 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24595?
Check the references section above for vendor advisories and patch information. Affected products include: Clear Clearml.