CVE-2024-12880

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 285

Summary

CVE-2024-12880 is a vulnerability affecting infiniflow/ragflow version RAGFlow-0.13.0. This issue allows for partial account takeover through insecure data querying related to the handling of tenant IDs. Users with access to multiple tenants can manipulate their tenant access to obtain API tokens of other tenants. Affected endpoints include /v1/system/token_list, /v1/system/new_token, /v1/api/token_list, /v1/api/new_token, and /v1/api/rm. An attacker can exploit this vulnerability to access other tenants' API tokens, impersonate them, and gain unauthorized access to their data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share