Логотип exploitDog
bind:CVE-2024-7819
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7819

Количество 2

Количество 2

nvd логотип

CVE-2024-7819

11 месяцев назад

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2c36-wq4v-5v3h

11 месяцев назад

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7819

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2c36-wq4v-5v3h

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу