Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xgj-c5fx-5v57

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

DB-GPT Uncontrolled Resource Consumption vulnerability

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests.

Пакеты

Наименование

dbgpt

pip
Затронутые версииВерсия исправления

<= 0.6.0

Отсутствует

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests.

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835