Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv5m-2pf6-cgmr

Опубликовано: 22 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

EPSS

Процентиль: 12%
0.00041
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
nvd
7 месяцев назад

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

EPSS

Процентиль: 12%
0.00041
Низкий

8.8 High

CVSS3

Дефекты

CWE-639