A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lollms
Lollms lollms Web Ui |
|
CPEs | cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lollms
Lollms lollms Web Ui |
|
Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Parisneo
Parisneo lollms-webui |
|
CPEs | cpe:2.3:a:parisneo:lollms-webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Parisneo
Parisneo lollms-webui |
|
Metrics |
ssvc
|
Tue, 29 Oct 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information. | |
Title | Data Leak through CORS Misconfiguration in parisneo/lollms-webui | |
Weaknesses | CWE-346 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-29T12:46:44.950Z
Updated: 2024-10-29T13:41:08.667Z
Reserved: 2024-07-10T20:35:32.781Z
Link: CVE-2024-6674
Vulnrichment
Updated: 2024-10-29T13:40:59.439Z
NVD
Status : Analyzed
Published: 2024-10-29T13:15:08.263
Modified: 2024-11-01T20:34:18.697
Link: CVE-2024-6674
Redhat
No data.