SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-9617

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files.

MEDIUM 6.5EPSS 1.66%

Does this matter?

Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.

Description

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-639
Source
security@huntr.dev

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.