CVE-2024-7767 Information
Mar 21, 2025
cve
Description
An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view modify and delete chats created by an Admin. This can lead to unauthorized access to sensitive information loss of data integrity and potential compliance violations.
Reference
https://huntr.com/bounties/1425dada-72d8-4bd9-a3e7-2863bb3e1a6c https://huntr.com/bounties/1425dada-72d8-4bd9-a3e7-2863bb3e1a6c
Share on: