CRITICAL🇵🇱 Wersja polska

CVE-2024-5823

CVSS 9.1v3.1pub. 2024-10-29upd. 2024-10-31

A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation.

🤖 AI Analysis
How it works

The vulnerability results from insufficient access control to file paths (CWE-73 — external control of filename, CWE-610 — externally controlled resource reference). An attacker without any credentials can send a network request causing configuration files on the system to be overwritten. Manipulation of these files allows changes to application settings or its security, and in extreme cases leads to disruption of its normal operation.

Impact

An attacker can unauthorized overwrite critical configuration files, resulting in changes to the application's behavior or security settings. Further abuse may lead to a denial of service (DoS) state, preventing normal system operation.

Mitigation & patch

The application should be updated to a version containing the fix available in commit 720c23d755a4a955dcb0a54e8c200a2247a27f8b in the manufacturer's GitHub repository. It is also recommended to restrict network access to application instances and review permissions for critical configuration files.

Who is affected

gaizhenbiao/ChuanhuChatGPT in versions <= 20240410

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Gaizhenbiao Chuanhuchatgpt

    APP
    Gaizhenbiao
    ≤ 2024-04-10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2024-5982CRITICAL9.8PL ✓same product

Path Traversal i RCE w ChuanhuChatGPT — niezabezpieczone dane wejściowe

CVE-2024-6036CRITICAL9.1PL ✓same product

Nieautoryzowany restart serwera w ChuanhuChatGPT poprzez endpoint /queue/join

CVE-2024-6037CRITICAL9.1PL ✓same product

Tworzenie arbitralnych folderów na serwerze w ChuanhuChatGPT

CVE-2024-5822CRITICAL9.8PL ✓same product

SSRF w interfejsie upload ChuanhuChatGPT — dostęp do zasobów wewnętrznych

CVE-2024-3234CRITICAL9.8PL ✓same product

Path traversal w ChuanhuChatGPT — dostęp do poufnych plików