CVE-2024-3135
CVSS V2 None
CVSS V3 None
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment.
Overview
- CVE ID
- CVE-2024-3135
- Assigner
- @huntr_ai
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-01T18:45:07.253Z
- Last Modified Date
- 2024-04-16T11:10:25.797Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://huntr.com/bounties/7afdc4d3-4b68-45ea-96d0-cf9ed3712ae8 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-3135 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3135 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-23 23:11:23 | Added to TrackCVE |