Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot, leading to internal Slack access. This issue was patched in version 3.63.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-26T20:46:33.551Z

Updated: 2024-08-02T02:20:35.603Z

Reserved: 2024-04-19T14:07:11.230Z

Link: CVE-2024-32881

cve-icon Vulnrichment

Updated: 2024-07-24T20:36:20.558Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-26T21:15:49.450

Modified: 2024-04-29T12:42:03.667

Link: CVE-2024-32881

cve-icon Redhat

No data.