In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access to sensitive information. The vulnerability is present in the application's handling of access control for the `history` path, where no adequate mechanism is in place to prevent an authenticated user from accessing another user's chat history files. This issue poses a significant risk as it could allow attackers to obtain sensitive information from the chat history of other users.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-284 | 
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-863 | |
| References |  | 
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Gaizhenbiao Gaizhenbiao chuanhuchatgpt | |
| CPEs | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:* | |
| Vendors & Products | Gaizhenbiao Gaizhenbiao chuanhuchatgpt | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:45:12.500Z
Updated: 2025-10-15T12:49:37.176Z
Reserved: 2024-04-05T18:12:08.080Z
Link: CVE-2024-3404
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T20:12:06.467Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-06-06T19:16:01.673
Modified: 2025-10-15T13:15:43.100
Link: CVE-2024-3404
 Redhat
                        Redhat
                    No data.