Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3033

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 9.1
CVSS3: 9.4
EPSS Низкий

Описание

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database and deleting specific namespaces, without requiring any authorization or permissions. The issue affects all versions up to and including the latest version, with a fix introduced in version 1.0.0. Exploitation of this vulnerability can lead to complete data loss of document embeddings across all workspaces, rendering workspace chats and embeddable chat widgets non-functional. Additionally, attackers can list all namespaces, potentially exposing private workspace names.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Версия до 1.0.0 (исключая)

EPSS

Процентиль: 35%
0.00145
Низкий

9.1 Critical

CVSS3

9.4 Critical

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.1
github
больше 1 года назад

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database and deleting specific namespaces, without requiring any authorization or permissions. The issue affects all versions up to and including the latest version, with a fix introduced in version 1.0.0. Exploitation of this vulnerability can lead to complete data loss of document embeddings across all workspaces, rendering workspace chats and embeddable chat widgets non-functional. Additionally, attackers can list all namespaces, potentially exposing private workspace names.

EPSS

Процентиль: 35%
0.00145
Низкий

9.1 Critical

CVSS3

9.4 Critical

CVSS3

Дефекты

CWE-863
CWE-863