NA - CVE-2024-10830 - A Path Traversal vulnerability exists in the...
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server...
NA - CVE-2024-10831 - In eosphoros-ai/db-gpt version 0.6.0, the...
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary...
NA - CVE-2024-10833 - eosphoros-ai/db-gpt version 0.6.0 is vulnerable...
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path...
NA - CVE-2024-10834 - eosphoros-ai/db-gpt version 0.6.0 contains a...
eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call...
NA - CVE-2024-10835 - In eosphoros-ai/db-gpt version v0.6.0, the web...
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by...
NA - CVE-2024-10901 - In eosphoros-ai/db-gpt version v0.6.0, the web...
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by...
NA - CVE-2024-10902 - In eosphoros-ai/db-gpt version v0.6.0, the web...
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to...
NA - CVE-2024-10906 - In version 0.6.0 of eosphoros-ai/db-gpt, the...
In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for...
NA - CVE-2024-10907 - In lm-sys/fastchat Release v0.2.36, the server...
In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests...
NA - CVE-2024-10908 - An open redirect vulnerability in...
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited...