The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
id: CVE-2024-9617
info:
name: Danswer - Insecure Direct Object Reference
author: s4e-io
sever
...