We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to admin users. This can lead to excessive resource consumption, potentially resulting in a Denial of Service (DoS) and other significant issues, impacting the system's stability and security.
Reserved 2024-08-21 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-284 Improper Access Control
huntr.com/bounties/b5991b98-a721-4acd-8ef2-980e15682913
Support options