8.6 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Chroma through 1.5.9 Authorization Bypass via Collection Identifier
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
References
-
GitHub Issue #7462 issue-tracking
-
the shared collection auth helper resolves the collection before checking the path technical-description
-
the provider caches and returns by collection id without comparing the database technical-description
Affected products
- =<1.5.9
Matching in nixpkgs
pkgs.chroma
General purpose syntax highlighter in pure Go
pkgs.chromaprint
AcoustID audio fingerprinting library
pkgs.polychromatic
Graphical front-end and tray applet for configuring Razer peripherals on GNU/Linux
pkgs.gnomeExtensions.achroma
Toggle your display to monochrome/grayscale mode with a single click. Useful for reducing eye strain, improving focus, or accessibility.
pkgs.python313Packages.chromadb
AI-native open-source embedding database
pkgs.python314Packages.chromadb
AI-native open-source embedding database
pkgs.python313Packages.chroma-hnswlib
Header-only C++/python library for fast approximate nearest neighbors
pkgs.python314Packages.chroma-hnswlib
Header-only C++/python library for fast approximate nearest neighbors
pkgs.pkgsRocm.python3Packages.chromadb
AI-native open-source embedding database
pkgs.python313Packages.langchain-chroma
Integration package connecting Chroma and LangChain
pkgs.python314Packages.langchain-chroma
Integration package connecting Chroma and LangChain
pkgs.pkgsRocm.python3Packages.langchain-chroma
Integration package connecting Chroma and LangChain
pkgs.python313Packages.llama-index-vector-stores-chroma
LlamaIndex Vector Store Integration for Chroma
pkgs.python314Packages.llama-index-vector-stores-chroma
LlamaIndex Vector Store Integration for Chroma
-
nixos-unstable -
- nixos-unstable-small 0.5.5
pkgs.pkgsRocm.python3Packages.llama-index-vector-stores-chroma
LlamaIndex Vector Store Integration for Chroma
Package maintainers
-
@MiniHarinn Harinn <prinn.dev@pm.me>
-
@honnip Jung seungwoo <me@honnip.page>
-
@sarahec Sarah Clark <seclark@nextquestion.net>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@natsukium Tomoya Otabi <nixpkgs@natsukium.com>
-
@nadir-ishiguro nadir-ishiguro
-
@evanjs Evan Stoll <evanjsx@gmail.com>