Логотип exploitDog
bind:CVE-2024-9617
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9617

Количество 2

Количество 2

nvd логотип

CVE-2024-9617

11 месяцев назад

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2w2q-qp7m-7wrh

11 месяцев назад

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-9617

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

CVSS3: 6.5
17%
Средний
11 месяцев назад
github логотип
GHSA-2w2q-qp7m-7wrh

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

CVSS3: 6.5
17%
Средний
11 месяцев назад

Уязвимостей на страницу