PT-2024-38028 · Unknown · Mudler/Localai

CVE-2024-7010

·

Published

2024-10-29

·

Updated

2024-11-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mudler/localai version 2.17.1
Description The issue is a Timing Attack, a type of side-channel attack that allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. In the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
Recommendations For mudler/localai version 2.17.1, consider implementing measures to mitigate timing attacks, such as adding random delays to the server's response time or using a constant-time comparison function for password verification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7010

Affected Products

Mudler/Localai