PT-2024-24937 · Slack+1 · Slack Bot+1

Laluka

·

Published

2024-04-26

·

Updated

2025-10-29

·

CVE-2024-32881

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Danswer versions prior to 3.63
Description Danswer, the AI Assistant connected to a company's documents, applications, and people, is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. This vulnerability allows anyone with network access to steal and set Slack bot tokens, leading to the full compromise of the customer's Slack bot and internal Slack access.
Recommendations For versions prior to 3.63, update to version 3.63 or later to resolve the issue. As a temporary workaround, consider restricting network access to the Danswer AI Assistant to minimize the risk of exploitation. Additionally, restrict access to the Slack Bot Tokens to prevent unauthorized GET/SET operations.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-32881
GHSA-XR9W-3GGR-HR6J

Affected Products

Answer
Slack Bot