In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page. Consequently, attackers can directly call the API to access the functionalities provided by the search page, bypassing the visibility restriction set by the administrator.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 03 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Onyx Onyx onyx | |
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:onyx:onyx:0.3.94:*:*:*:*:*:*:* | |
| Vendors & Products | Onyx Onyx onyx | |
| Metrics | cvssV3_1 
 | 
Thu, 20 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page. Consequently, attackers can directly call the API to access the functionalities provided by the search page, bypassing the visibility restriction set by the administrator. | |
| Title | Unauthorized Access in danswer-ai/danswer | |
| Weaknesses | CWE-1100 | |
| References |  | |
| Metrics | cvssV3_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:08.077Z
Updated: 2025-03-20T13:34:33.986Z
Reserved: 2024-10-07T22:22:35.791Z
Link: CVE-2024-9612
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-20T13:34:21.605Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-03-20T10:15:49.560
Modified: 2025-04-03T18:10:11.190
Link: CVE-2024-9612
 Redhat
                        Redhat
                    No data.