Home » Database

AVID-2026-R1438

Description

Vulnerability CVE-2024-24593

Details

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.

Reason for inclusion in AVID: CVE-2024-24593 describes a cross-site request forgery vulnerability in the API server component of Allegro AI’s ClearML platform. ClearML is an AI/ML workflow management platform widely used in ML pipelines for experiment tracking, data handling, and deployment. A CSRF vulnerability enabling impersonation and access to confidential workspaces/files constitutes a security vulnerability with direct impact on AI software stacks. The issue affects a software component used to build/deploy/run general-purpose AI systems, making it a relevant supply-chain risk in GP AI contexts. The report provides explicit vulnerability behavior, scope, and references (CVE/NVD).

References

Affected or Relevant Artifacts

  • Developer: Allegro.AI
  • Deployer: Allegro.AI
  • Artifact Details:
TypeName
SystemClearML

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score9.6
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-352CWE-352 Cross-Site Request Forgery (CSRF)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-02-06
  • Version: 0.3.3
  • AVID Entry