PT-2024-36826 · Unknown · Free-One-Api

Kexinoh

·

Published

2024-12-30

·

Updated

2024-12-30

·

CVE-2024-56516

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions free-one-api versions up to and including 1.0.1
Description The issue concerns the use of MD5, a cryptographically broken hashing algorithm, to hash passwords before sending them to the backend. This makes it vulnerable to collision attacks and can be easily cracked using modern hardware, exposing user credentials to potential compromise. The free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format.
Recommendations For versions up to and including 1.0.1, consider disabling password hashing using MD5 until a secure replacement is implemented. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-56516
GHSA-36CC-58VM-WM4H

Affected Products

Free-One-Api