CVE-2024-7010

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-29 13:15

Updated : 2024-11-14 14:15


NVD link : CVE-2024-7010

Mitre link : CVE-2024-7010

CVE.ORG link : CVE-2024-7010


JSON object : View

Products Affected

mudler

  • localai
CWE
CWE-203

Observable Discrepancy