Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12910

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A vulnerability in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the get_article_urls method, exhausting system resources and potentially crashing the application.

A flaw was found in the run-llama/llama_index repository. This vulnerability allows an attacker to cause a denial of service (DoS) by controlling a URL variable to contain the root URL, leading to infinite recursive calls to the get_article_urls method and exhausting system resources.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-service-api-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2353537llama-index: Denial of Service in run-llama/llama_index

EPSS

Процентиль: 50%
0.00271
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
11 месяцев назад

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the `get_article_urls` method, exhausting system resources and potentially crashing the application.

CVSS3: 5.9
github
11 месяцев назад

LlamaIndex Uncontrolled Resource Consumption vulnerability

EPSS

Процентиль: 50%
0.00271
Низкий

4.2 Medium

CVSS3