VYPR

Label Studio

by Heartex

CVEs (1)

  • CVE-2022-36551MedOct 3, 2022
    risk 0.39cvss 6.5epss 0.05

    A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of…