CVE-2024-7010

CVSS V2 None CVSS V3 None
Description
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
Overview
  • CVE ID
  • CVE-2024-7010
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-29T12:48:29.287Z
  • Last Modified Date
  • 2024-10-29T13:30:36.920Z
History
Created Old Value New Value Data Type Notes
2024-10-30 13:18:52 Added to TrackCVE