In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access to sensitive information. The vulnerability is present in the application's handling of access control for the `history` path, where no adequate mechanism is in place to prevent an authenticated user from accessing another user's chat history files. This issue poses a significant risk as it could allow attackers to obtain sensitive information from the chat history of other users.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
CPEs | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gaizhenbiao
Gaizhenbiao chuanhuchatgpt |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:45:12.500Z
Updated: 2024-08-01T20:12:06.467Z
Reserved: 2024-04-05T18:12:08.080Z
Link: CVE-2024-3404
Vulnrichment
Updated: 2024-08-01T20:12:06.467Z
NVD
Status : Modified
Published: 2024-06-06T19:16:01.673
Modified: 2024-11-21T09:29:31.663
Link: CVE-2024-3404
Redhat
No data.