Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-2217

Опубликовано: 10 апр. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the config.json file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (openai_api_key, google_palm_api_key, xmchat_api_key, etc.), configuration details, and user credentials. The issue stems from the application's handling of HTTP requests for the config.json file, which does not properly restrict access based on user authentication.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240121:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
github
почти 2 года назад

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (`openai_api_key`, `google_palm_api_key`, `xmchat_api_key`, etc.), configuration details, and user credentials. The issue stems from the application's handling of HTTP requests for the `config.json` file, which does not properly restrict access based on user authentication.

EPSS

Процентиль: 42%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo