CVE Vulnerabilities

CVE-2024-12869

Improper Authentication

Published: Mar 20, 2025 | Modified: Apr 01, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another users invite list. This can lead to a privacy breach where users personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ragflow Infiniflow 0.12.0 (including) 0.12.0 (including)

Potential Mitigations

References