CVE-2024-43779

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clear:clearml_enterprise_server:3.22.5-1533:*:*:*:*:*:*:*

History

05 Sep 2025, 17:44

Type Values Removed Values Added
CPE cpe:2.3:a:clear:clearml_enterprise_sever:3.22.5-1533:*:*:*:*:*:*:* cpe:2.3:a:clear:clearml_enterprise_server:3.22.5-1533:*:*:*:*:*:*:*
First Time Clear clearml Enterprise Server

05 Sep 2025, 17:27

Type Values Removed Values Added
CWE CWE-522
CPE cpe:2.3:a:clear:clearml_enterprise_sever:3.22.5-1533:*:*:*:*:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 - Exploit, Third Party Advisory
First Time Clear clearml Enterprise Sever
Clear
Summary
  • (es) Existe una vulnerabilidad de divulgación de información en la funcionalidad Vault API de ClearML Enterprise Server 3.22.5-1533. Una solicitud HTTP especialmente manipulada puede provocar la lectura de bóvedas que se han deshabilitado previamente, lo que puede provocar la filtración de credenciales confidenciales. Un atacante puede enviar una serie de solicitudes HTTP para activar esta vulnerabilidad.

06 Feb 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2112 -

06 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 17:15

Updated : 2025-09-05 17:44


NVD link : CVE-2024-43779

Mitre link : CVE-2024-43779

CVE.ORG link : CVE-2024-43779


JSON object : View

Products Affected

clear

  • clearml_enterprise_server
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials