Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files. This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only. Version 1.0.330 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Agnai
Agnai agnai |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:* | |
Vendors & Products |
Agnai
Agnai agnai |
Thu, 26 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files. This only affects installations with `JSON_STORAGE` enabled which is intended to local/self-hosting only. Version 1.0.330 fixes this issue. | |
Title | Agnai File Disclosure Vulnerability: JSON via Path Traversal | |
Weaknesses | CWE-35 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-26T17:16:21.950Z
Updated: 2024-09-26T17:16:21.950Z
Reserved: 2024-09-19T22:32:11.961Z
Link: CVE-2024-47170
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2024-09-26T18:15:10.370
Modified: 2024-10-29T20:59:57.227
Link: CVE-2024-47170
Redhat
No data.