In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access to sensitive information. The vulnerability is present in the application's handling of access control for the `history` path, where no adequate mechanism is in place to prevent an authenticated user from accessing another user's chat history files. This issue poses a significant risk as it could allow attackers to obtain sensitive information from the chat history of other users.
History

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
CPEs cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:*
Vendors & Products Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-06T18:45:12.500Z

Updated: 2024-08-01T20:12:06.467Z

Reserved: 2024-04-05T18:12:08.080Z

Link: CVE-2024-3404

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:06.467Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T19:16:01.673

Modified: 2024-11-21T09:29:31.663

Link: CVE-2024-3404

cve-icon Redhat

No data.