CVE-2024-12880

A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants, they can manipulate their tenant access to query and access API tokens of other tenants. This vulnerability affects the following endpoints: /v1/system/token_list, /v1/system/new_token, /v1/api/token_list, /v1/api/new_token, and /v1/api/rm. An attacker can exploit this to access other tenants' API tokens, perform actions on behalf of other tenants, and access their data.
References
Link Resource
https://huntr.com/bounties/c41c7eaa-554a-408c-96be-9dba56113970 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:infiniflow:ragflow:0.13.0:*:*:*:*:*:*:*

History

14 Jul 2025, 18:20

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la versión RAGFlow-0.13.0 de infiniflow/ragflow permite la apropiación parcial de cuentas mediante consultas de datos inseguras. El problema surge de la forma en que se gestionan los ID de inquilino en la aplicación. Si un usuario tiene acceso a varios inquilinos, puede manipular su acceso para consultar y acceder a los tokens de API de otros inquilinos. Esta vulnerabilidad afecta a los siguientes endpoints: /v1/system/token_list, /v1/system/new_token, /v1/api/token_list, /v1/api/new_token y /v1/api/rm. Un atacante puede explotar esto para acceder a los tokens de API de otros inquilinos, realizar acciones en su nombre y acceder a sus datos.
First Time Infiniflow
Infiniflow ragflow
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 6.5
References () https://huntr.com/bounties/c41c7eaa-554a-408c-96be-9dba56113970 - () https://huntr.com/bounties/c41c7eaa-554a-408c-96be-9dba56113970 - Exploit, Third Party Advisory
CPE cpe:2.3:a:infiniflow:ragflow:0.13.0:*:*:*:*:*:*:*

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-14 18:20


NVD link : CVE-2024-12880

Mitre link : CVE-2024-12880

CVE.ORG link : CVE-2024-12880


JSON object : View

Products Affected

infiniflow

  • ragflow
CWE
CWE-285

Improper Authorization