VulnerabilityDeferred
CVE-2024-9617
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files.
MEDIUM 6.5EPSS 1.66%
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Source
- security@huntr.dev
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.