Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xph7-9rjv-w5fr

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.8

Описание

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

EPSS

Процентиль: 14%
0.00237
Низкий

8.8 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.8
redhat
9 дней назад

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

CVSS3: 8.8
nvd
9 дней назад

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

EPSS

Процентиль: 14%
0.00237
Низкий

8.8 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-863