PT-2024-24131 · Mintplex · Anything-Llm

Published

2024-06-06

·

Updated

2024-09-20

·

CVE-2024-3153

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm (affected versions not specified)
Description The issue is related to an uncontrolled resource consumption vulnerability in the upload file endpoint, which can lead to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability to upload documents can exploit this vulnerability to cause a DOS condition by manipulating the upload request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-3153

Affected Products

Anything-Llm