Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4fj-pp9j-x2mj

Опубликовано: 07 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-367