FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.
An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Primary | cve.org | 7.8 | — | — |
| 3.1 | Secondary | NVD | 7.8 | 1.8 | 5.9 |
| 3.1 | Secondary | NVD | 7.8 | 1.8 | 5.9 |
| 3.1 | Secondary | ENISA EUVD | 7.8 | — | — |