Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connecting the victim's application with a malicious Slack Bot, inviting users, and deleting chats, among other actions. The application does not implement any CSRF protection, making it susceptible to these attacks.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-8065?
CVE-2024-8065 is a vulnerability with a CVSS score of 8.1 (HIGH). A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connect...
How severe is CVE-2024-8065?
CVE-2024-8065 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-8065?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.