PT-2025-12169 · Unknown · Anything-Llm

CVE-2024-6842

·

Publicado

2025-03-20

·

Atualizado

2025-07-15

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm version 1.5.5
Description The issue allows unauthorized users to access sensitive system settings through the "/setup-complete" API endpoint. The data returned by the currentSettings function includes sensitive information, such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.
Recommendations For version 1.5.5, consider disabling access to the "/setup-complete" API endpoint until a patch is available to prevent unauthorized access to sensitive system settings. Restrict the use of the currentSettings function to authorized users only to minimize the risk of exploitation.

Exploit

Correção

DoS

Missing Authentication

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-6842

Produtos afetados

Anything-Llm