Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2024-32881

Disclosure Date: April 26, 2024 (last updated April 27, 2024)
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot, leading to internal Slack access. This issue was patched in version 3.63.
0
Attacker Value
Unknown

CVE-2023-4815

Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
Attacker Value
Unknown

CVE-2023-4127

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.
Attacker Value
Unknown

CVE-2023-4126

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-4125

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-4124

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
Attacker Value
Unknown

CVE-2023-2590

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.
Attacker Value
Unknown

CVE-2023-1976

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6.
Attacker Value
Unknown

CVE-2023-1975

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.
Attacker Value
Unknown

CVE-2023-1974

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.