Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33r9-m4vj-8h9p

Опубликовано: 13 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

EPSS

Процентиль: 33%
0.0013
Низкий

7.1 High

CVSS3

Дефекты

CWE-352
CWE-400

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

EPSS

Процентиль: 33%
0.0013
Низкий

7.1 High

CVSS3

Дефекты

CWE-352
CWE-400