PT-2024-38594 · Unknown · Gaizhenbiao/Chuanhuchatgpt
Published
2024-10-29
·
Updated
2025-07-14
·
CVE-2024-7807
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
gaizhenbiao/chuanhuchatgpt version 20240628
Description
A Denial of Service (DOS) attack can be performed by appending a large number of characters to the end of a
multipart boundary when uploading a file. This causes the system to continuously process each character, leading to uncontrolled resource consumption and rendering the service inaccessible. The attack can result in prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.Recommendations
For gaizhenbiao/chuanhuchatgpt version 20240628, consider restricting file uploads or limiting the size of uploaded files to prevent the Denial of Service attack until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gaizhenbiao/Chuanhuchatgpt