Описание
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
Уязвимые конфигурации
Конфигурация 1Версия от 0.5.0 (включая) до 1.5.9 (включая)
cpe:2.3:a:trychroma:chromadb:*:*:*:*:*:python:*:*
EPSS
Процентиль: 21%
0.00284
Низкий
8.8 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-639
CWE-551
Связанные уязвимости
CVSS3: 8.1
redhat
около 2 месяцев назад
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
CVSS3: 8.8
github
около 2 месяцев назад
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
EPSS
Процентиль: 21%
0.00284
Низкий
8.8 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-639
CWE-551