PT-2024-39324 · Unknown · Ilab Model Serve

Thibault Guittet

·

Published

2024-09-17

·

Updated

2024-09-20

·

CVE-2024-8939

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ilab model serve component (affected versions not specified)
Description: A vulnerability was found in the ilab model serve component, where improper handling of the best of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-based sentence or chat completion accepts a best of parameter to return the best completion from several options. When this parameter is set to a large value, the API does not handle timeouts or resource exhaustion properly, allowing an attacker to cause a DoS by consuming excessive system resources. This leads to the API becoming unresponsive, preventing legitimate users from accessing the service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-8939
GHSA-WC36-9694-F9RF

Affected Products

Ilab Model Serve