CVE-2024-43779

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clear:clearml_enterprise_server:3.22.5-1533:*:*:*:*:*:*:*

History

05 Sep 2025, 17:44

Type Values Removed Values Added
First Time Clear clearml Enterprise Server
CPE cpe:2.3:a:clear:clearml_enterprise_sever:3.22.5-1533:*:*:*:*:*:*:* cpe:2.3:a:clear:clearml_enterprise_server:3.22.5-1533:*:*:*:*:*:*:*

05 Sep 2025, 17:27

Type Values Removed Values Added
CPE cpe:2.3:a:clear:clearml_enterprise_sever:3.22.5-1533:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de divulgación de información en la funcionalidad Vault API de ClearML Enterprise Server 3.22.5-1533. Una solicitud HTTP especialmente manipulada puede provocar la lectura de bóvedas que se han deshabilitado previamente, lo que puede provocar la filtración de credenciales confidenciales. Un atacante puede enviar una serie de solicitudes HTTP para activar esta vulnerabilidad.
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - Exploit, Third Party Advisory
First Time Clear clearml Enterprise Sever
Clear
CWE CWE-522

06 Feb 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 -

06 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 17:15

Updated : 2025-09-05 17:44


NVD link : CVE-2024-43779

Mitre link : CVE-2024-43779

CVE.ORG link : CVE-2024-43779


JSON object : View

Products Affected

clear

  • clearml_enterprise_server
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials