Unauthorized access to GET/SET of Slack Bot Tokens in Danswer
Vulnerability Description
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot, leading to internal Slack access. This issue was patched in version 3.63.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32881
Credits & Attribution
No credits recorded in the NVD database.
References
More from danswer-ai
View All →Affected Vendor
danswer-ai
View all reports →