Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kotaemon Missing Ownership Check in Conversation Functions
Vulnerability Description
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Cinnamon kotaemon 授权问题漏洞
Vulnerability Description
Cinnamon kotaemon是Cinnamon团队开源的一个文档协作与问答平台。 Cinnamon kotaemon 0.12.0及之前版本存在授权问题漏洞,该漏洞源于control.py文件中的select_conv、delete_conv、rename_conv和on_set_public_conversation函数未能正确验证会话所有权,导致攻击者可通过提供任意会话标识符读取其他用户的聊天记录、删除会话或重命名会话。
CVSS Information
N/A
Vulnerability Type
N/A