Improper Authentication Vulnerability in Ragflow by Infiniflow
CVE-2024-12869
What is CVE-2024-12869?
In Ragflow version v0.12.0 by Infiniflow, an improper authentication issue has been identified that permits unauthorized users to access another user's invite list. This vulnerability compromises user privacy by disclosing sensitive information, such as email addresses and usernames, potentially leading to further cybersecurity threats like phishing attacks, spam, and a loss of user trust. Organizations employing this software should investigate the vulnerability to mitigate data leakage risks and maintain compliance with privacy regulations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
infiniflow/ragflow <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
