CVE-2024-8057
CVSS 3.0 Score 4.3 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 284
Summary
CVE-2024-8057 is a vulnerability affecting version 0.4.1 of danswer-ai/danswer. This issue enables a basic user to create credentials and link them to an existing connector, allowing unauthenticated attackers to sign up and perform actions reserved for admin users. Consequences include excessive resource consumption, leading to potential Denial of Service (DoS) attacks and other stability and security concerns. This vulnerability undermines the intended access control mechanisms, posing a significant risk to the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.