CVE-2024-6831
published 2024-11-26CVE-2024-6831: Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due…
PriorityP418medium4.4CVSS 3.1
AVLACLPRLUINSUCNILAL
EPSS
0.16%
5.2th percentile
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check.
Axis has released patched versions for the highlighted flaw. Please
refer to the Axis security advisory for more information and solution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis_communications_ab | axis_camera_station | — | — |
| axis_communications_ab | axis_camera_station_pro | — | — |
| lfprojects | mlflow | 0 – 2.9.2 | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
ghsa8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f3wf-2g4f-5hv8: Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permi
ghsa_unreviewed·2024-11-26
CVE-2024-6831 [MEDIUM] CWE-602 GHSA-f3wf-2g4f-5hv8: Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permi
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check.
Axis has released patched versions for the highlighted flaw. Please
refer to the Axis security advisory for more information and solution.
GHSA
mlflow vulnerable to Path Traversal
ghsa·2024-04-16·CVSS 8.1
CVE-2024-1560 [HIGH] CWE-22 mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the `_delete_artifact_mlflow_artifacts` handler and `local_file_uri_to_path` function, allowing for the deletion of arbitrary directories on the server's filesystem. This vulnerability is due to an extra unquote operation in the `delete_artifacts` function of `local_artifact_repo.py`, which fails to properly sanitize user-supplied paths. The issue is present up to version 2.9.2, despite attempts to fix a similar issue in CVE-2023-6831.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-26
Published