PT-2025-12288 · Unknown · Danswer-Ai/Danswer

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-9612

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions danswer-ai/danswer version 0.3.94
Description The issue allows attackers to bypass the visibility restriction set by administrators for the search page. When the search page is set to be invisible, regular users cannot view it or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page, enabling attackers to directly call the API to access the search page's functionalities.
Recommendations For version 0.3.94, consider restricting access to the API endpoints related to the search page until a patch is available. As a temporary workaround, administrators can also limit the functionality of the search page to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9612

Affected Products

Danswer-Ai/Danswer