Description
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.
References (3)
Core 3
Core References
Various Sources
https://github.com/gian2dchris/CVEs/tree/main/CVE-2024-40441
Release Notes
https://github.com/doccano/doccano/releases/tag/v1.8.4
Scores
CVSS v3
6.6
EPSS
0.0060
EPSS Percentile
69.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-918
Status
published
Published
Sep 23, 2024
Tracked Since
Feb 18, 2026