CVE-2024-31451: GHSL-2023-250: Unauthenticated limited file write in DocsGPT - CVE-2024-31451
Published Apr 16, 2024
·Updated
DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1.
Affected Software
1 affected component
DocsGPT<0.8.1
Event History
Apr 16, 2024
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Apr 18, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31451?
CVE-2024-31451 is classified as a moderate severity vulnerability due to its potential for limited file write access.
2
How do I fix CVE-2024-31451?
To fix CVE-2024-31451, update DocsGPT to version 0.8.1 or later.
3
What component of DocsGPT is affected by CVE-2024-31451?
CVE-2024-31451 affects the routes.py component of DocsGPT.
4
Is CVE-2024-31451 an authenticated vulnerability?
CVE-2024-31451 is an unauthenticated vulnerability, allowing limited file write access without user authentication.
5
Which versions of DocsGPT are vulnerable to CVE-2024-31451?
All versions of DocsGPT prior to 0.8.1 are vulnerable to CVE-2024-31451.