mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.
History

Thu, 31 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mintplexlabs
Mintplexlabs anythingllm
CPEs cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Vendors & Products Mintplexlabs
Mintplexlabs anythingllm
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 29 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Miniplex Labs
Miniplex Labs miniplex Labs\/anything Lim
CPEs cpe:2.3:a:miniplex_labs:miniplex_labs\/anything_lim:*:*:*:*:*:*:*:*
Vendors & Products Miniplex Labs
Miniplex Labs miniplex Labs\/anything Lim
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
Description mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.
Title Improper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llm
Weaknesses CWE-312
References
Metrics cvssV3_0

{'score': 5.9, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-10-29T12:49:34.965Z

Updated: 2024-10-29T13:27:53.212Z

Reserved: 2024-08-14T00:35:02.915Z

Link: CVE-2024-7783

cve-icon Vulnrichment

Updated: 2024-10-29T13:27:40.442Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T13:15:10.137

Modified: 2024-10-31T15:49:02.870

Link: CVE-2024-7783

cve-icon Redhat

No data.