
PEACH
Un cadre d’isolation des locataires
A vulnerability identified as CVE-2024-12880 was discovered in infiniflow/ragflow version RAGFlow-0.13.0, which allows for partial account takeover through insecure data querying. The vulnerability was initially reported on March 20, 2025, and last modified on October 15, 2025. The issue specifically affects the application's handling of tenant IDs and multiple endpoints including /v1/system/tokenlist, /v1/system/newtoken, /v1/api/tokenlist, /v1/api/newtoken, and /v1/api/rm (NVD).
The vulnerability stems from improper authorization controls in the tenant ID handling mechanism. When users have access to multiple tenants, they can manipulate their tenant access to query and access API tokens of other tenants. The vulnerability has received varying CVSS scores, with the NVD assigning a CVSS 3.1 Base Score of 6.5 (MEDIUM) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, while huntr.dev assessed it at 8.1 (HIGH) with vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H. The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key) (NVD, Huntr).
The vulnerability enables attackers to access other tenants' API tokens, perform actions on behalf of other tenants, and access their data. This represents a significant security breach in multi-tenant environments, potentially compromising data confidentiality and tenant isolation (NVD).
No specific mitigation strategies or patches have been publicly disclosed at this time. Organizations using RAGFlow-0.13.0 should monitor for updates from the vendor and consider implementing additional access controls and tenant isolation mechanisms (NVD).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."