Unauthenticated Denial of Service (DoS) in mintplex-labs/anything-llm
Vulnerability Description
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the API endpoint, causing a server crash due to an uncaught exception. This issue is fixed in version 1.2.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8249
Credits & Attribution
No credits recorded in the NVD database.
References
More from mintplex-labs
View All →Affected Vendor
mintplex-labs
View all reports →