An issue in Doccano Open source annotation tools for...
Moderate severity
Unreviewed
Published
Sep 23, 2024
to the GitHub Advisory Database
•
Updated Sep 25, 2024
Description
Published by the National Vulnerability Database
Sep 23, 2024
Published to the GitHub Advisory Database
Sep 23, 2024
Last updated
Sep 25, 2024
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.
References