Database/AI/ML frameworks & serving

ClearML: Passwords stored in plaintext in MongoDB
CVSS 6.0CVE-2024-24595AI/ML frameworks & servingcurated
Impact
Passwords stored in plaintext in MongoDB
Who can reach it
Anyone who compromises the ClearML server
What to do
Upgrade; rotate all credentials after any exposure
References
Related entries
- JupyterLab: authenticated users bypass administrator plugin lock rules via /lab/api/pluginsCVE-2026-73627 · JupyterLab Extension/Plugin Manager (/lab/api/plugins lock-rule enforcement)Medium
- Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETECVE-2026-27482 · Ray (dashboard DELETE endpoints)Medium
- LocalAI (`/models/apply`): SSRF and partial local file inclusionCVE-2024-6095 · LocalAI (`/models/apply`)Medium
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingCVE-2026-65087 · NVIDIA NemoClaw (credential storage)Medium
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsCVE-2022-49784 · Linux perf/x86/amd/uncore - memory leak in the events arrayMedium
- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelCVE-2024-31584 · PyTorch (flatbuffer loader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.