漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
Vulnerability Description
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier predicates in the chunk model semanticSearch method. Attackers can supply arbitrary victim file or knowledge-base identifiers through the chunk retrieval and chat knowledge-base paths to retrieve text content, file names, and metadata belonging to other users.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
LobeHub LobeChat 授权问题漏洞
Vulnerability Description
LobeHub是LobeHub团队开源的一个全平台AI对话框架。 LobeHub LobeChat 2.2.9及之前版本存在授权问题漏洞,该漏洞源于检索增强生成语义搜索功能的访问控制失效,允许经过身份验证的攻击者通过利用chunk model语义搜索方法中缺失的用户标识符谓词,访问其他用户的数据。攻击者可以通过chunk检索和聊天知识库路径提供任意受害者文件或知识库标识符,检索属于其他用户的文本内容、文件名和元数据。
CVSS Information
N/A
Vulnerability Type
N/A