CVE-2024-24595

Publication date

2024-02-05 21:15:19

Family

HiddenLayer

State

PUBLISHED

Description

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.