CVE-2023-38976: Incorrect Type Cast
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-8697-479h-5mfp. This link is maintained to preserve external references.
Original Description An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.
Other sources
Impact This vulnerability is a type conversion issue that affects users of Weaviate Server versions 1.20.0 and earlier. Who is impacted: Users of Weaviate Server versions 1.20.0 and earlier are impacted by this vulnerability.
Patches A patch has been developed for this vulnerability. Patch releases 1.20.6, 1.19.13, and 1.18.6 are fixing this vulnerability in each respective minor version release. Users are strongly recommended to upgrade to one of these patched versions to address the vulnerability. Keeping software up-to-date is crucial to avoid security vulnerabilities.
Workarounds There are no known workarounds to fix or remediate this vulnerability without upgrading. Users must upgrade to a patched version to mitigate the risk.
References https://github.com/weaviate/weaviate/releases/tag/v1.18.6 https://github.com/weaviate/weaviate/releases/tag/v1.19.13 https://github.com/weaviate/weaviate/releases/tag/v1.20.6
An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38976?
CVE-2023-38976 has not been assigned a specific severity rating but involves a denial of service vulnerability.
Which versions of Weaviate are affected by CVE-2023-38976?
CVE-2023-38976 affects Weaviate version 1.20.0 and earlier versions below 1.19.13.
How do I fix CVE-2023-38976?
To fix CVE-2023-38976, update Weaviate to version 1.20.6 or later, or to at least version 1.19.13.
What types of attacks does CVE-2023-38976 enable?
CVE-2023-38976 enables remote attackers to cause a denial of service, impacting the availability of the affected service.
Is CVE-2023-38976 a standalone vulnerability?
No, CVE-2023-38976 has been withdrawn as it is a duplicate of GHSA-8697-479h-5mfp.