Danswer Improper Access Control Vulnerability Allowing Unauthorized Chat Management
Vulnerability
An improper access control vulnerability has been identified in Danswer version 0.3.94. This issue allows the first user created in the system to view, modify, and delete chats created by an Admin. Such access can result in unauthorized exposure of sensitive information, disruption of data integrity, and potential violations of compliance regulations.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, manipulation or deletion of data, and potential compliance violations.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
6.6remediation
0.0relevance
0.0threat
6.4urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
