疑似Oday
Chroma DB API endpoints were accessible and exposed collection metadata, enabling enumeration of collections under the default tenant and database, potentially leading to sensitive vector data disclosure.
id: chroma-db-unauth
info:
name: Chroma DB - Information Disclosure
author: Shay Ben Tikva
se
...