Clear develops machine learning operations and data-management platforms, including ClearML workflow software and ClearSpot appliances, where vulnerability exposure concentrates around web-application and authentication-layer issues. The recurring weakness classes—cross-site scripting, CSRF, insufficiently protected credentials, untrusted deserialization, and forced-browsing flaws—reflect the web-facing and API-driven architecture of these management and integration tools, and vulnerabilities affecting the vendor reach moderate severity outcomes. Current exploitation activity, severity distribution, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clear over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4507HIGH Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hi | Dec 30, 2010 | 9.3 | 41 | NO | YES |
CVE-2024-24590HIGH Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitra | Feb 6, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-24592CRITICAL Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files. | Feb 6, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-24593HIGH A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate | Feb 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24591HIGH A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files | Feb 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39272HIGH A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbi | Feb 6, 2025 | 8.2 | 23 | NO | NO |
CVE-2024-43779MEDIUM An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults | Feb 6, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-24594MEDIUM A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload whe | Feb 6, 2024 | 5.4 | 20 | NO | NO |
CVE-2024-24595HIGH Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
| Feb 5, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-6778MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. | Dec 18, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clear.
Media articles that mention a CVE ID that affects a product developed by Clear — matched by CVE ID, not by vendor name.