CVE-2024-7767

HIGH

onyx - Missing Authorization

Title source: llm
STIX 2.1

Description

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
onyx/onyx 0.3.94
Published Mar 20, 2025
Tracked Since Feb 18, 2026