Vulnerability Description
A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hliu | Llava | 1.2.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/cd793f83-f122-432b-83e7-1cc8c78817b7ExploitThird Party Advisory
FAQ
What is CVE-2024-10225?
CVE-2024-10225 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request....
How severe is CVE-2024-10225?
CVE-2024-10225 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10225?
Check the references section above for vendor advisories and patch information. Affected products include: Hliu Llava.