CVE-2024-24593 CRITICAL

CVE-2024-24593

Vendor Allegro.ai
Product ClearML
Weakness CWE-352 · CSRF
Published February 6, 2024
Last update June 17, 2025

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.

Key dates

02Disclosure timeline

February 6, 2024 CVE published
June 17, 2025 Record updated

Related vulnerabilities

04Related CVE