PT-2023-26715 · Weaviate · Weaviate

Published

2023-08-21

·

Updated

2023-11-02

·

CVE-2023-38976

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Weaviate versions 1.20.0 and earlier
Description The issue is a type conversion problem that allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function. This affects users of Weaviate Server versions 1.20.0 and earlier.
Recommendations For Weaviate version 1.20.0, upgrade to version 1.20.6 to address the vulnerability. For Weaviate version 1.19.x, upgrade to version 1.19.13 to address the vulnerability. For Weaviate version 1.18.x, upgrade to version 1.18.6 to address the vulnerability. As a temporary workaround, consider disabling the handleUnbatchedGraphQLRequest function until a patch is available.

Exploit

Fix

Incorrect Type Conversion or Cast

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38976
GHSA-8697-479H-5MFP
GHSA-CH6W-MC6C-G65G
GO-2023-2017

Affected Products

Weaviate