PT-2024-36826 · Unknown · Free-One-Api
Kexinoh
·
Published
2024-12-30
·
Updated
2024-12-30
·
CVE-2024-56516
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
free-one-api versions up to and including 1.0.1
Description
The issue concerns the use of MD5, a cryptographically broken hashing algorithm, to hash passwords before sending them to the backend. This makes it vulnerable to collision attacks and can be easily cracked using modern hardware, exposing user credentials to potential compromise. The free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format.
Recommendations
For versions up to and including 1.0.1, consider disabling password hashing using MD5 until a secure replacement is implemented.
As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free-One-Api