Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m95h-p4gg-wfw3: Allegro AI ClearML path traversal vulnerability

A path traversal vulnerability in version 1.4.0 or newer of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.

ghsa
#vulnerability#git

Allegro AI ClearML path traversal vulnerability

High severity GitHub Reviewed Published Feb 6, 2024 to the GitHub Advisory Database • Updated Feb 6, 2024

ghsa: Latest News

GHSA-7xqm-7738-642x: File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing