anything-llm是Mintplex开源的一个一体式桌面和 Docker AI 应用程序。 anything-llm 1.5.5版本存在信息泄露漏洞,该漏洞源于/setup-complete API端点未授权访问,可能导致敏感信息泄露。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| mintplex-labs | mintplex-labs/anything-llm | unspecified ~ 1.0.2 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | AnythingLLM suffers from an information disclosure vulnerability through the `/api/setup-complete` API endpoint. By accessing this endpoint, a remote and unauthenticated attacker can access sensitive configuration of the target AnythingLLM instance. This detection is included in the AI and LLM category. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6842.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2024-13060 | AnythingLLM 安全漏洞 | |
| CVE-2024-7771 | anything-llm 资源管理错误漏洞 | |
| CVE-2024-8196 | anything-llm 访问控制错误漏洞 | |
| CVE-2024-8248 | anything-llm 安全漏洞 | |
| CVE-2024-8251 | anything-llm 输入验证错误漏洞 | |
| CVE-2024-8249 | AnythingLLM 安全漏洞 | |
| CVE-2024-10109 | anything-llm 安全漏洞 | |
| CVE-2024-10513 | AnythingLLM 安全漏洞 |
暂无评论