CVE-2024-7783

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-29 13:15

Updated : 2024-10-31 15:49


NVD link : CVE-2024-7783

Mitre link : CVE-2024-7783

CVE.ORG link : CVE-2024-7783


JSON object : View

Products Affected

mintplexlabs

  • anythingllm
CWE
CWE-312

Cleartext Storage of Sensitive Information