Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh3j-9m59-p8vc

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

BentoML vulnerable to Uncontrolled Resource Consumption

In bentoml/bentoml version 1.3.9, the /login endpoint of the newly integrated Gradio app is vulnerable to a Denial of Service (DoS) attack. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction.

Пакеты

Наименование

bentoml

pip
Затронутые версииВерсия исправления

<= 1.3.9

Отсутствует

7.5 High

CVSS3

Дефекты

CWE-400

7.5 High

CVSS3

Дефекты

CWE-400