PT-2025-12151 · Unknown · Infiniflow/Ragflow
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-12869
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
infiniflow/ragflow version v0.12.0
Description
The issue is related to improper authentication, allowing a user to view another user's invite list. This can lead to a privacy breach, exposing personal or private information such as email addresses or usernames without consent. The exposed data can facilitate further attacks like phishing or spam, resulting in loss of trust and potential regulatory issues.
Recommendations
For infiniflow/ragflow version v0.12.0, update to a version that fixes the improper authentication issue to prevent unauthorized access to invite lists. As a temporary workaround, consider restricting access to invite lists until a patch is available.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infiniflow/Ragflow