CVE-2022-31188
Published on: Not Yet Published
Last Modified on: 12/08/2022 10:35:00 PM UTC
Certain versions of Cvat from Cvat contain the following vulnerability:
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.
- CVE-2022-31188 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
cvat-ai - cvat version < 2.0.0
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Added validation for URLs which used as remote data source (#4387) · cvat-ai/[email protected] · GitHub | github.com text/html |
![]() |
SSRF Vulnerability in CVAT · Advisory · cvat-ai/cvat · GitHub | github.com text/html |
![]() |
CVAT 2.0 Server-Side Request Forgery ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cvat | Cvat | All | All | All | All |
- cpe:2.3:a:cvat:cvat:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-31188 : CVAT is an opensource interactive video and image annotation tool for computer vision. Versions pr… twitter.com/i/web/status/1… | 2022-08-01 20:00:33 |
![]() |
CVE-2022-31188 | 2022-08-01 20:38:21 |