Impact
An attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and subdirectories. The contents of files are not accessible.
Patches
Update to CVAT 2.53.0 or a later version.
Workarounds
N/A
References
Fix commit: 2c24ef0
Impact
An attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and subdirectories. The contents of files are not accessible.
Patches
Update to CVAT 2.53.0 or a later version.
Workarounds
N/A
References
Fix commit: 2c24ef0