PT-2025-12288 · Unknown · Danswer-Ai/Danswer
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-9612
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
danswer-ai/danswer version 0.3.94
Description
The issue allows attackers to bypass the visibility restriction set by administrators for the search page. When the search page is set to be invisible, regular users cannot view it or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page, enabling attackers to directly call the API to access the search page's functionalities.
Recommendations
For version 0.3.94, consider restricting access to the API endpoints related to the search page until a patch is available. As a temporary workaround, administrators can also limit the functionality of the search page to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Danswer-Ai/Danswer