Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot, leading to internal Slack access. This issue was patched in version 3.63.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-26T20:46:33.551Z

Updated: 2024-04-26T20:46:33.551Z

Reserved: 2024-04-19T14:07:11.230Z


Link: CVE-2024-32881

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-26T21:15:49.450

Modified: 2024-04-29T12:42:03.667


Link: CVE-2024-32881

JSON object: View

cve-icon Redhat Information

No data.

CWE