CVE-2024-7010 Vulnerability Details

  /     /     /  

CVE-2024-7010 Metadata Quick Info

CVE Published: 29/10/2024 | CVE Updated: 14/11/2024 | CVE Year: 2024
Source: @huntr_ai | Vendor: mudler | Product: mudler/localai
Status : PUBLISHED

CVE-2024-7010 Description

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server\'s response time, potentially leading to unauthorized access.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-203
CWE Name: CWE-203 Observable Discrepancy
Source: mudler

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).