ClearML Enterprise Server Cross-Site Scripting Vulnerability in Dataset Upload Functionality

Vulnerability

A cross-site scripting vulnerability has been identified in ClearML Enterprise Server versions 3.22.5-1533. This issue arises in the dataset upload feature, where a specially crafted HTTP request can inject arbitrary HTML. Attackers can exploit this vulnerability by sending a series of HTTP requests to upload malicious HTML files into a dataset. These files may then be rendered in the browser of an authenticated ClearML user, executing any JavaScript contained within the HTML. This vulnerability could lead to the exfiltration of sensitive data from the user's local storage, particularly information related to storage providers like AWS S3.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser. This could lead to the execution of malicious JavaScript, potentially allowing attackers to access and exfiltrate sensitive data from the user's local storage.

Remediation

Users are advised to update to the latest version of ClearML Enterprise Server, where this vulnerability has been patched. Additionally, consider implementing a strict Content Security Policy to limit script execution sources and sanitizing HTML content before upload.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.