Логотип exploitDog
bind:CVE-2024-5182
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-5182

Количество 2

Количество 2

nvd логотип

CVE-2024-5182

больше 1 года назад

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. Specifically, by crafting a request with a manipulated `model` parameter, an attacker can traverse the directory structure and target files outside of the intended directory, leading to the deletion of sensitive data. This vulnerability is due to insufficient input validation and sanitization of the `model` parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-cpcx-r2gq-x893

больше 1 года назад

LocalAI path traversal vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-5182

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. Specifically, by crafting a request with a manipulated `model` parameter, an attacker can traverse the directory structure and target files outside of the intended directory, leading to the deletion of sensitive data. This vulnerability is due to insufficient input validation and sanitization of the `model` parameter.

CVSS3: 9.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-cpcx-r2gq-x893

LocalAI path traversal vulnerability

CVSS3: 7.5
2%
Низкий
больше 1 года назад

Уязвимостей на страницу