github.com
https://github.com/gaizhenbiao/chuanhuchatgpt/commit/ccc7479ace5c9e1a1d9f4daf2e794ffd3865fc2b CVE-2024-8143
MEDIUM
Unauthorized Access to User Chat History in gaizhenbiao/chuanhuchatgpt
Record summary
CVE-2024-8143 has a selected CVSS score of 4.3 (medium).
Description
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
chuanhuchatgptBrowse gaizhenbiao / chuanhuchatgptDefault status: unknown | CVE List | 20240628 | affected |
gaizhenbiao/chuanhuchatgptBrowse gaizhenbiao / gaizhenbiao/chuanhuchatgpt | CVE List | Before 20240919 | affected |
References
3huntr.com
https://huntr.com/bounties/71c5ea4b-524a-4173-8fd4-2fbabd69502e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8143