CVE-2024-11167
Last modified
CVE-2024-11167 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Librechat | Librechat | < 0.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-11167?
How severe is CVE-2024-11167?
How do I fix CVE-2024-11167?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-11158An “uninitialized variable” code execution vulnerability exi…8.5
- CVE-2024-11159Using remote content in OpenPGP encrypted messages can lead …4.3
- CVE-2024-1116A vulnerability was found in openBI up to 1.0.8. It has been…9.8
- CVE-2024-11160Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-11165An information disclosure vulnerability exists in the backup…5.7
- CVE-2024-11166For TCAS II systems using transponders compliant with MOPS e…7.1
- CVE-2024-11168The urllib.parse.urlsplit() and urlparse() functions imprope…6.3
- CVE-2024-11169An unhandled exception in danny-avila/librechat version 3c94…7.5
- CVE-2024-1117A vulnerability was found in openBI up to 1.0.8. It has been…9.8
- CVE-2024-11170A vulnerability in danny-avila/librechat version git 81f2936…8.8
- CVE-2024-11171In danny-avila/librechat version git 0c2a583, there is an im…7.5
- CVE-2024-11172A vulnerability in danny-avila/librechat version git a1647d7…7.5
Are you affected by CVE-2024-11167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
