PT-2024-35120 · Mintplex · Anything-Llm
Published
2024-06-19
·
Updated
2025-10-15
·
CVE-2024-5208
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
mintplex-labs/anything-llm (affected versions not specified)
Description
An uncontrolled resource consumption issue exists in the "upload-link" endpoint, allowing attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload requests. This can be achieved by sending an empty body with a 'Content-Length: 0' header or by sending a body with arbitrary content, such as 'asdasdasd', with a 'Content-Length: 9' header. The issue is reproducible by users with at least a 'Manager' role, sending a crafted request to any workspace. This indicates that a previous fix was not effective in mitigating the issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anything-Llm