CVE-2024-9612 Details
Description
In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page. Consequently, attackers can directly call the API to access the functionalities provided by the search page, bypassing the visibility restriction set by the administrator.
A vulnerability in Danswer version 0.3.94 allows administrators to control the visibility of pages within a workspace, including the search page. When the search page is made invisible, regular users cannot access it or its features from the front-end. However, the back-end fails to check the visibility status, enabling attackers to directly call the API and use the search page's functionalities, circumventing the administrator's restrictions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://huntr.com/bounties/c1046fa0-a719-475e-ba62-2b97873fbac4 | CISA-ADP | ExploitThird Party Advisory |
| https://huntr.com/bounties/c1046fa0-a719-475e-ba62-2b97873fbac4 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-1100 | Insufficient Isolation of System-Dependent Functions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| onyx onyx | 0.3.94 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Initial Analysis | [email protected] |
| Mar 20, 2025 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | New CVE Received | [email protected] |