HIGH
Create user API role not enforced
Published Mar 2, 2024
7.2
HIGHCVSS 3.1
EPSS 0.95%
Description
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplex-Labs | Mintplex-Labs/anything-Llm | n/a |
|
- < 1.0.0
-
- Version 0StatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplexlabs | Anythingllm | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16582 Advisory
- https://github.com/mintplex-labs/anything-llm/commit/9a237db3d1f66cdbcf5079599258f5fb251c5564 Patch
- https://huntr.com/bounties/f69e3307-7b44-4776-ac60-2990990723ec ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16582 | Advisory | |
| https://github.com/mintplex-labs/anything-llm/commit/9a237db3d1f66cdbcf5079599258f5fb251c5564 | Patch | |
| https://huntr.com/bounties/f69e3307-7b44-4776-ac60-2990990723ec | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 2, 2024
Updated Aug 15, 2024
Reserved Jan 22, 2024
Link CVE-2024-0795
CISA Vulnrichment
Updated Mar 8, 2024
ENISA EUVD
EUVD-2024-16582 Assigner @huntr_ai
Published Mar 2, 2024
Updated Aug 15, 2024
Exploited since n/a
Link EUVD-2024-16582