We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-9612

Unauthorized Access in danswer-ai/danswer



Description

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page. Consequently, attackers can directly call the API to access the functionalities provided by the search page, bypassing the visibility restriction set by the administrator.

Reserved 2024-10-07 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-1100 Insufficient Isolation of System-Dependent Functions

Product status

Any version
affected

References

huntr.com/bounties/c1046fa0-a719-475e-ba62-2b97873fbac4

cve.org (CVE-2024-9612)

nvd.nist.gov (CVE-2024-9612)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-9612

Support options

Helpdesk Chat, Email, Knowledgebase