CVE-2024-53450: High severity ragflow vulnerability
Published Dec 9, 2024
·Updated
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.
Affected Software
2 affected components
RAGFlow RAGFlow
infiniflow ragflow=0.13.0
Event History
Dec 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53450?
CVE-2024-53450 has been assigned a medium severity rating due to improper access control allowing unauthorized access to user documents.
2
How do I fix CVE-2024-53450?
To fix CVE-2024-53450, implement proper access control measures in the document-hooks.ts file to restrict unauthorized access.
3
What software is affected by CVE-2024-53450?
CVE-2024-53450 affects RAGFlow version 0.13.0.
4
What is the impact of CVE-2024-53450?
The impact of CVE-2024-53450 allows unauthorized users to access sensitive user documents.
5
Who discovered CVE-2024-53450?
CVE-2024-53450 was reported by security researchers analyzing the RAGFlow software.