CVE-2024-7010
CVSS V2 None
CVSS V3 None
Description
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
Overview
- CVE ID
- CVE-2024-7010
- Assigner
- @huntr_ai
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-29T12:48:29.287Z
- Last Modified Date
- 2024-10-29T13:30:36.920Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-7010 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7010 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-30 13:18:52 | Added to TrackCVE |