Prisma Vulnerability Allows Escalation of Privileges to Administrator
CVE-2024-3150

8.8HIGH

Key Information:

Vendor
Mintplex-labs
Status
Mintplex-labs/anything-llm
Vendor
CVE Published:
6 June 2024

Summary

A privilege escalation vulnerability exists in Anything LLM developed by Mintplex Labs, which is associated with a critical flaw in the thread update process. This flaw permits users with Default or Manager roles to gain Administrator privileges due to inadequate input validation during HTTP POST requests directed to the /workspace/:slug/thread/:threadSlug/update endpoint. The vulnerability allows malicious actors to manipulate the Prisma relation query operation intended for the workspace_thread model, enabling unauthorized changes to the users model to elevate their own user roles. This exploit results in attackers obtaining the highest levels of permissions within the application, granting them the ability to access and execute any action available within the system.

Affected Version(s)

mintplex-labs/anything-llm < 1.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.