CVE-2024-12880
CVSS 3.0 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-12880 is a vulnerability affecting infiniflow/ragflow version RAGFlow-0.13.0. This issue allows for partial account takeover through insecure data querying related to the handling of tenant IDs. Users with access to multiple tenants can manipulate their tenant access to obtain API tokens of other tenants. Affected endpoints include /v1/system/token_list, /v1/system/new_token, /v1/api/token_list, /v1/api/new_token, and /v1/api/rm. An attacker can exploit this vulnerability to access other tenants' API tokens, impersonate them, and gain unauthorized access to their data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.