In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infiniflow
Infiniflow ragflow |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:infiniflow:ragflow:0.12.0:*:*:*:*:*:*:* | |
Vendors & Products |
Infiniflow
Infiniflow ragflow |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues. | |
Title | Improper Authentication in infiniflow/ragflow | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:19.807Z
Updated: 2025-03-20T14:14:12.265Z
Reserved: 2024-12-20T20:12:36.931Z
Link: CVE-2024-12869

Updated: 2025-03-20T14:14:00.557Z

Status : Analyzed
Published: 2025-03-20T10:15:31.087
Modified: 2025-04-01T20:34:43.100
Link: CVE-2024-12869

No data.