Improper Authentication Vulnerability in Ragflow by Infiniflow
CVE-2024-12869

4.3MEDIUM

Key Information:

Vendor

Infiniflow

Vendor
CVE Published:
20 March 2025

What is CVE-2024-12869?

In Ragflow version v0.12.0 by Infiniflow, an improper authentication issue has been identified that permits unauthorized users to access another user's invite list. This vulnerability compromises user privacy by disclosing sensitive information, such as email addresses and usernames, potentially leading to further cybersecurity threats like phishing attacks, spam, and a loss of user trust. Organizations employing this software should investigate the vulnerability to mitigate data leakage risks and maintain compliance with privacy regulations.

Affected Version(s)

infiniflow/ragflow <= unspecified

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.