Junglewise Threat Intelligence

CVE-2023-43791: PYSEC-2023-274 - Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained

CVE-2023-43791 · Severity: low · CVSS 3.1 · Published 2023-11-09

Technologies: label-studio (PyPI). Vendors: PyPI.

Executive brief

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.

Affected products

  • PyPI label-studio

Related threats