Clearml

Latest version: v1.16.1

Vulnerabilities (9)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2022-29217 49693

Clearml 1.4.2rc0 updates its dependency 'pyjwt' requirement to versio…

  • <1.4.2rc0
HIGH 7.5
CVE-2024-24591 65006

Clearml 1.14.2 fixes potential path traversal on file download. http…

  • >=1.4.0,<1.14.1
HIGH 8.8
CVE-2024-24595 66778

Allegro AI’s open-source version of ClearML stores passwords in plain…

  • <=1.14.2
HIGH 7.1
CVE-2024-24593 66780

A cross-site request forgery (CSRF) vulnerability in all versions up …

  • <1.14.1
HIGH 8.8
PVE-2022-49700 49700

Clearml 1.0.6rc2 fixes unsafe Google Storage delete object. https://…

  • <1.0.6rc2
- -
PVE-2022-49701 49701

Clearml 0.17.5rc3 fixes unsafe call to set_active(). https://github.…

  • <0.17.5rc3
- -
CVE-2024-24590 65114

Clearml version 1.14.3 introduces a hash check for pickle files to ta…

  • >=0.17.0,<1.14.3
HIGH 8.8
CVE-2024-24592 66781

Lack of authentication in all versions of the fileserver component of…

  • >=0
CRITICAL 9.8
CVE-2024-24594 66779

A cross-site scripting (XSS) vulnerability in all versions of the web…

  • >=0
MEDIUM 5.4