CVE-2024-6674: Data Leak through CORS Misconfiguration in parisneo/lollms-webui
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6674?
CVE-2024-6674 is considered a critical security vulnerability due to its potential for sensitive information theft and unauthorized actions.
How do I fix CVE-2024-6674?
To resolve CVE-2024-6674, update lollms-webui to version 10 or later to address the CORS misconfiguration.
What types of sensitive information can be stolen due to CVE-2024-6674?
CVE-2024-6674 allows attackers to steal sensitive information such as logs, browser sessions, and private API keys.
Who is affected by CVE-2024-6674?
Any users of lollms-webui versions prior to 10 are affected by CVE-2024-6674.
What are the implications of exploiting CVE-2024-6674?
Exploiting CVE-2024-6674 can enable attackers to perform actions on behalf of the user and compromise sensitive data.