Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85qw-gwgm-xj6w

Опубликовано: 10 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 4.8

Описание

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

EPSS

Процентиль: 36%
0.00436
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 4.8
nvd
около 2 месяцев назад

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

EPSS

Процентиль: 36%
0.00436
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-306