The following table lists the changes that have been made to the
CVE-2024-56137 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jan. 02, 2025
Action Type Old Value New Value Added Description MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists in the module of function library. The vulnerability allow privileged users to execute OS command in custom scripts. The vulnerability has been fixed in v1.9.0. Added CVSS V3.1 AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H Added CWE CWE-78 Added Reference https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-76w2-2g72-cg85