Race Condition Vulnerability in mintplex-labs/anything-llm
Published May 6, 2024
6.5
MEDIUMCVSS 3.0
EPSS 0.33%
Description
A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=latest
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplex-Labs | Mintplex-Labs/anything-Llm | n/a |
|
- ≤ 1.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27856 Advisory
- https://huntr.com/bounties/a3c69faf-cca0-4c10-8739-57e5bef7a95f ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27856 | Advisory | |
| https://huntr.com/bounties/a3c69faf-cca0-4c10-8739-57e5bef7a95f | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.