2024-12-08 03:06:42 +00:00

64 lines
2.1 KiB
JSON

{
"id": "CVE-2024-48145",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-10-24T19:15:15.607",
"lastModified": "2024-10-28T20:35:18.340",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyecci\u00f3n r\u00e1pida en el cuadro de chat de Netangular Technologies ChatNet AI versi\u00f3n v1.0 permite a los atacantes acceder y filtrar todos los datos de chat anteriores y posteriores entre el usuario y el asistente de IA a trav\u00e9s de un mensaje manipulado espec\u00edficamente para ello."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"references": [
{
"url": "https://apps.microsoft.com/detail/9n3zxd05895t?hl=en-us&gl=US",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48145",
"source": "cve@mitre.org"
}
]
}