PT-2024-20457 · Lobe Chat · Lobe Chat

Dastaj

·

Published

2024-01-31

·

Updated

2024-02-09

·

CVE-2024-24566

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lobe Chat versions prior to 0.122.4
Description The issue allows access to plugins without proper authorization when the application is password-protected and deployed with the ACCESS CODE option. This means that even though the application requires a password to access the chat, plugins can still be interacted with without entering the password. For example, an HTTP request to the "/api/plugin/gateway" endpoint can be made without providing the ACCESS CODE, allowing unauthorized access to plugins.
Recommendations For versions prior to 0.122.4, update to version 0.122.4 or later to resolve the issue. As a temporary workaround, consider verifying the ACCESS CODE for HTTP requests to the /api/plugin/ route to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-24566
GHSA-PF55-FJ96-XF37

Affected Products

Lobe Chat