PT-2024-31469 · Unknown · Mage Ai Framework
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mage AI framework (affected versions not specified)
Description
The issue concerns guest users in the Mage AI framework who remain logged in after their accounts are deleted. These users are mistakenly given high privileges, specifically access to remotely execute arbitrary code through the Mage AI terminal server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Session Expiration
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mage Ai Framework