PYSEC-2024-316

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-316.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-316
Aliases
Published
2024-04-10T17:15:54.440Z
Modified
2026-07-13T07:15:20.080849161Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the config.json file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (openai_api_key, google_palm_api_key, xmchat_api_key, etc.), configuration details, and user credentials. The issue stems from the application's handling of HTTP requests for the config.json file, which does not properly restrict access based on user authentication.

References

Affected packages

PyPI / chuanhuchatgpt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
20240121

Affected versions

3.*
3.2.5

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-316.yaml"