ChromaDB Installer - Detected
Detects the presence of the ChromaDB admin interface.The endpoint reveals connection details and authentication type.
Chroma DBPoC 已收录
CVSS—
共找到 3 条公开漏洞记录
Detects the presence of the ChromaDB admin interface.The endpoint reveals connection details and authentication type.
ChromaDB runs without authentication by default, exposing the API edpoint to anyone and allowing unauthorized access to read.
Chroma DB API endpoints were accessible and exposed collection metadata, enabling enumeration of collections under the default tenant and database, potentially leading to sensitive vector data disclosure.