PT-2024-27145 · Oneflow · Oneflow
Published
2024-06-06
·
Updated
2025-05-02
·
CVE-2024-36737
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Oneflow version 0.9.1
Description
The issue is related to improper input validation, allowing attackers to cause a Denial of Service (DoS) by inputting a negative value into the
oneflow.full parameter.Recommendations
For version 0.9.1, avoid using negative values in the
oneflow.full parameter to prevent Denial of Service attacks. As a temporary workaround, consider validating user input to ensure it does not contain negative values.Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oneflow