PT-2025-12151 · Unknown · Infiniflow/Ragflow

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-12869

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions infiniflow/ragflow version v0.12.0
Description The issue is related to improper authentication, allowing a user to view another user's invite list. This can lead to a privacy breach, exposing personal or private information such as email addresses or usernames without consent. The exposed data can facilitate further attacks like phishing or spam, resulting in loss of trust and potential regulatory issues.
Recommendations For infiniflow/ragflow version v0.12.0, update to a version that fixes the improper authentication issue to prevent unauthorized access to invite lists. As a temporary workaround, consider restricting access to invite lists until a patch is available.

Exploit

Fix

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12869

Affected Products

Infiniflow/Ragflow