opea-project / GenAIExamples

Generative AI Examples is a collection of GenAI examples such as ChatQnA, Copilot, which illustrate the pipeline capabilities of the Open Platform for Enterprise AI (OPEA) project.
https://opea.dev
Apache License 2.0
286 stars 195 forks source link

[bug] ChatQnA Security Assessment (It is not a Security Audit) #1220

Open dehatideep opened 2 hours ago

dehatideep commented 2 hours ago

Priority

Undecided

OS type

Other (Please let us know in description)

Hardware type

CPU-other (Please let us know in description)

Installation method

Deploy method

Running nodes

Single Node

What's the version?

2b2c7ee2f5221432dc6020d006436b380a00e52e

Description

ChatQnA security Assessment: https://docs.google.com/document/d/1df20UOmqJ_30VW5i6MajxXbJn3KhwVHfxYo3oGt2W5o/edit?usp=sharing

Reproduce steps

See the security assessment details. These are based upon code reading.

Raw log

See the security assessment details. These are based upon code reading.
dehatideep commented 2 hours ago

@arun-gupta https://github.com/opea-project/GenAIExamples/issues/1220