Danswer < 0.10.0-beta.1 Insecure Direct Object Reference

medium Web App Scanning Plugin ID 114467

Synopsis

Danswer < 0.10.0-beta.1 Insecure Direct Object Reference

Description

Danswer version prior to 0.10.0-beta.1 suffers from an Insecure Direct Object Reference allowing an unauthenticated attacker to access messages and attached files via a specially forged request. This detection is included in the AI and LLM category.

Solution

Upgrade to Danswer 0.10.0-beta.1 or later and authentication should be enforced to prevent unauthorized access to the Danswer interface.

See Also

https://huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146

https://www.danswer.ai/

Plugin Details

Severity: Medium

ID: 114467

Type: remote

Published: 10/29/2024

Updated: 10/29/2024

Scan Template: basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:danswer-ai:danswer:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/1/2024

Vulnerability Publication Date: 10/1/2024

Reference Information

CVE: CVE-2024-9617