CVE-2024-12869: Improper Authentication in infiniflow/ragflow
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12869?
CVE-2024-12869 is classified as a medium severity vulnerability due to its potential to cause privacy breaches.
How do I fix CVE-2024-12869?
To fix CVE-2024-12869, update to the latest version of infiniflow/ragflow that patches the improper authentication flaw.
What does CVE-2024-12869 affect?
CVE-2024-12869 affects infiniflow/ragflow version v0.12.0 and earlier versions.
Can CVE-2024-12869 lead to data exposure?
Yes, CVE-2024-12869 can lead to unauthorized access to another user's invite list, resulting in potential data exposure.
Is there a workaround for CVE-2024-12869 until a fix is applied?
Currently, there are no known workarounds for CVE-2024-12869; users should upgrade to a fixed version as soon as possible.