Description

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.

INFO

Published Date :

2025-03-20T10:11:20.256Z

Last Modified :

2025-10-15T12:49:51.871Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7767 vulnerability.

Vendors Products
Onyx
  • Onyx
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7767.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact