CVE-2024-8057
MEDIUMdanswer-ai/danswer < latest - Unauthenticated Privilege Escalation via Connector Credential Linking
Title source: llmDescription
In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to admin users. This can lead to excessive resource consumption, potentially resulting in a Denial of Service (DoS) and other significant issues, impacting the system's stability and security.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/b5991b98-a721-4acd-8ef2-980e15682913
Scores
CVSS v3
4.3
EPSS
0.0039
EPSS Percentile
30.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
danswer-ai/danswer-ai/danswer
unspecified - latest
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026