CVE-2024-7957

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 29

Summary

CVE-2024-7957 is a newly disclosed vulnerability affecting the latest version of danswer-ai/danswer's ZulipConnector. The issue stems from the 'load_credentials' method, which utilizes user-controlled input for 'realm_name' and 'zuliprc_content' to construct file paths and write file contents. This creates an arbitrary file overwrite vulnerability, enabling attackers to overwrite or create arbitrary files if a 'zuliprc-' directory exists in the temporary directory.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share