CVE-2024-2913

CVSS V2 None CVSS V3 None
Description
A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.
Overview
  • CVE ID
  • CVE-2024-2913
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-06T23:42:10.887Z
  • Last Modified Date
  • 2024-06-04T17:29:29.985Z
References
History
Created Old Value New Value Data Type Notes
2024-06-25 23:28:33 Added to TrackCVE