We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-3569

Denial of Service (DoS) Vulnerability in mintplex-labs/anything-llm



Assigner@huntr_ai
Reserved2024-04-10
Published2024-04-10
Updated2024-08-01

Description

A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware with a specially crafted 'Authorization:' header. This vulnerability leads to uncontrolled resource consumption, causing a DoS condition.



HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Any version before 1.0.0
affected

References

https://huntr.com/bounties/619e13bd-b723-4727-9ccb-5099d698432e

https://github.com/mintplex-labs/anything-llm/commit/efe9dfa5e3550d12abd34d06ab7f8fbcf2206cfa

cve.org CVE-2024-3569

nvd.nist.gov CVE-2024-3569

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.