Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations.
VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
About this summary. This is a short, independently written summary of an article first published by CERT/CC. Cyber Security News did not report or verify the underlying story. Read the original: https://kb.cert.org/vuls/id/754548
Source attribution: headline and facts are from CERT/CC (kb.cert.org). Summary method: excerpt of the source description. See our source attribution policy.

