PT-2025-12196 · Unknown · Danswer-Ai/Danswer
Published
2025-03-20
·
Updated
2025-03-22
·
CVE-2024-7819
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
danswer-ai/danswer version 1.4.1
Description
A CORS misconfiguration allows attackers to steal sensitive information such as chat contents, API keys, and other data. This issue occurs due to improper validation of the
origin header, enabling malicious web pages to make unauthorized requests to the application's API.Recommendations
For version 1.4.1, consider implementing proper validation of the
origin header to prevent unauthorized requests. As a temporary workaround, restrict access to sensitive API endpoints to minimize the risk of exploitation.Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Danswer-Ai/Danswer