Label StudioGHSA-pc6f-259w-w3j6
Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module
High6.5CVE-2022-36551 · Published Oct 4, 2022 · updated Sep 27, 2024
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF. This issue is fixed in version 1.6.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| label-studio PyPI | < 1.6.0 | 1.6.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2022-36551, PYSEC-2022-300
- nvd.nist.gov/vuln/detail/CVE-2022-36551
- github.com/heartexlabs/label-studio/pull/2840
- github.com/heartexlabs/label-studio/commit/501142cb815ac964b0c600c491885b67386870c2
- github.com/heartexlabs/label-studio
- github.com/heartexlabs/label-studio/releases/tag/1.6.0
- github.com/pypa/advisory-database/tree/main/vulns/label-studio/PYSEC-2022-300.yaml
- heartex.com
- labelstud.io
- packetstormsecurity.com/files/171548/Label-Studio-1.5.0-Server-Side-Request-Forgery.html
More Label Studio advisories
All Label Studio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 312024 | Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections | Medium5.3 | 1.11.0 |
| Jan 242024 | Cross-site Scripting Vulnerability on Data Import | Medium4.7 | 1.10.1 |
| Jan 242024 | Cross-site Scripting Vulnerability on Avatar Upload | High7.1 | 1.9.2 |
| Nov 142023 | Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task | High7.5 | 1.9.2.post0 |
| Nov 92023 | Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens | Critical9.8 | 1.8.2 |
| Mar 242023 | Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/ | High7.5 | 1.7.2 |