Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x97m-f58v-9cwg

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.8

Описание

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

EPSS

Процентиль: 21%
0.00284
Низкий

8.8 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-551
CWE-639

Связанные уязвимости

CVSS3: 8.1
redhat
около 2 месяцев назад

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

CVSS3: 8.8
nvd
около 2 месяцев назад

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

EPSS

Процентиль: 21%
0.00284
Низкий

8.8 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-551
CWE-639