CVE-2024-8613

Source
https://cve.org/CVERecord?id=CVE-2024-8613
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8613.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-8613
Aliases
Published
2025-03-20T10:11:38Z
Modified
2026-08-12T03:51:32Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Improper Access Control in gaizhenbiao/chuanhuchatgpt
Details

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8613.json"
}
References

Affected packages

Git / github.com/gaizhenbiao/chuanhuchatgpt

Affected ranges

Type
GIT
Repo
https://github.com/gaizhenbiao/chuanhuchatgpt
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240802:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "20240802"
        },
        {
            "last_affected": "20240802"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

Other
20240802
20240914

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8613.json"