S4E just found a critical cve-2022-27924 scanner
high·Product Based Web Vulnerabilities·Updated Sep 16, 2024

CVE-2024-6842 Scanner

CVE-2024-6842 scanner - Information Disclosure vulnerability in AnythingLLM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6842
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mintplex-labs/anything-llmby mintplex-labs
AFFECTED< 1.0.2SAFE ✓≥ 1.0.2
Updated Aug 22, 2026View on NVD →
Detail

AnythingLLM is a language model management tool commonly used by developers and companies to manage AI models and streamline the implementation of large language models (LLMs) in various applications. It allows seamless integration of AI-powered functions and is used across industries for automation, research, and data analysis. The platform offers flexibility with multiple API options for AI integrations. By handling sensitive configurations, the software is vital in the AI deployment process. Protecting this software from vulnerabilities is critical to maintaining the security of sensitive user data.

The vulnerability allows unauthorized access to the /api/setup-complete endpoint of the AnythingLLM application. By exploiting this vulnerability, attackers can view sensitive configuration details, including API keys and tokens. The issue arises due to improper protection of sensitive configuration data. Attackers do not need authentication to exploit this weakness, making the vulnerability highly critical.

The vulnerability resides in the /api/setup-complete API endpoint of AnythingLLM. When accessed by an unauthenticated user, this endpoint reveals sensitive information such as API keys, search engine credentials, and authentication tokens. The system does not properly restrict access to this endpoint, allowing attackers to retrieve sensitive data with ease. The response header shows an application/json content type, and the status code of 200 confirms successful access. The parameters exposed include Google and Bing search API keys, which can lead to significant security breaches.

Exploiting this vulnerability could allow attackers to gain unauthorized access to sensitive system configurations, including API keys and tokens. This could result in unauthorized access to connected services, including search engine integrations or other AI services, leading to information leaks. Attackers could use this information to compromise the integrity and confidentiality of the system, allowing them to perform further attacks or unauthorized actions on the affected system.

By using S4E's platform, you can easily detect and manage vulnerabilities like this one in your systems. Our Cyber Threat Exposure Management platform continuously scans your digital assets and reports any security vulnerabilities or misconfigurations, helping you protect sensitive information before attackers can exploit it. Become a member today and stay ahead of potential threats with real-time monitoring, expert guidance, and detailed remediation steps, all in a user-friendly SaaS platform designed for businesses of all sizes.

References:

Solution Advice
  • Restrict access to the /api/setup-complete endpoint.
  • Implement authentication and authorization checks for sensitive endpoints.
  • Rotate and invalidate any exposed API keys or tokens.
  • Update to the latest version of AnythingLLM where the vulnerability has been fixed.
  • Regularly monitor and audit access logs to detect unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-6842 scanner - Information Disclosure vulnerability in AnythingLLM S4E