CVE-2024-6090

Source
https://cve.org/CVERecord?id=CVE-2024-6090
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6090.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6090
Aliases
Published
2024-06-27T18:40:51.125Z
Modified
2026-08-12T03:51:31.114239114Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Path Traversal Vulnerability in gaizhenbiao/chuanhuchatgpt
Details

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in .json on the target system, leading to a denial of service as users are unable to authenticate.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6090.json"
}
References

Affected packages

Git / github.com/gaizhenbiao/chuanhuchatgpt

Affected ranges

Type
GIT
Repo
https://github.com/gaizhenbiao/chuanhuchatgpt
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "20240410"
        },
        {
            "last_affected": "20240410"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*"
}

Affected versions

Other
20240410
20240628
20240802
20240914

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6090.json"