Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3429

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 9.8
CVSS3: 9.8
EPSS Низкий

Описание

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the sanitize_path_from_endpoint and sanitize_path functions in lollms_core\lollms\security.py. This vulnerability allows for arbitrary file reading when the application is running on Windows. The issue arises due to insufficient sanitization of user-supplied input, enabling attackers to bypass the path traversal protection mechanisms by crafting malicious input. Successful exploitation could lead to unauthorized access to sensitive files, information disclosure, and potentially a denial of service (DoS) condition by including numerous large or resource-intensive files. This vulnerability affects the latest version prior to 9.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lollms:lollms:*:*:*:*:*:*:*:*
Версия до 9.6 (исключая)

EPSS

Процентиль: 44%
0.00212
Низкий

9.8 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-29
CWE-22

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

LoLLMS Path Traversal vulnerability

EPSS

Процентиль: 44%
0.00212
Низкий

9.8 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-29
CWE-22