CVE-2024-7010

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*

History

15 Oct 2025, 13:15

Type Values Removed Values Added
CWE CWE-208

Information

Published : 2024-10-29 13:15

Updated : 2025-10-15 13:15


NVD link : CVE-2024-7010

Mitre link : CVE-2024-7010

CVE.ORG link : CVE-2024-7010


JSON object : View

Products Affected

mudler

  • localai
CWE
CWE-208

Observable Timing Discrepancy

CWE-203

Observable Discrepancy