CVE-2024-1569

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.
Configurations

No configuration.

History

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 -
References () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e -

16 Apr 2024, 13:24

Type Values Removed Values Added
Summary
  • (es) parisneo/lollms-webui es vulnerable a un ataque de denegación de servicio (DoS) debido al consumo incontrolado de recursos. Los atacantes pueden explotar `/open_code_in_vs_code` y endpoints similares sin autenticación enviando solicitudes HTTP POST repetidas, lo que lleva a la apertura de Visual Studio Code o del abridor de carpeta predeterminado (por ejemplo, Explorador de archivos, xdg-open) varias veces. Esto puede inutilizar la máquina host al agotar los recursos del sistema. La vulnerabilidad está presente en la última versión del software.

16 Apr 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-16 00:15

Updated : 2024-11-21 08:50


NVD link : CVE-2024-1569

Mitre link : CVE-2024-1569

CVE.ORG link : CVE-2024-1569


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption