CVE-2024-24566 describes an authorization bypass vulnerability in Lobe Chat, a chatbot framework, specifically affecting instances protected by an ACCESS_CODE. Attackers can access plugins without providing the required password, leading to unauthorized information disclosure (CVSS 5.3 MEDIUM). While the vulnerability is easily exploitable over the network with low attack complexity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. The issue has been resolved in Lobe Chat version 0.122.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.122.4CPE matchmatch criteria | cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.