CVE-2024-11169: Unhandled Exception Leading to Server Crash in danny-avila/librechat
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is fixed in version 0.7.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11169?
CVE-2024-11169 has a severity rating that indicates a potential for an unauthorized server crash due to unhandled exceptions.
How do I fix CVE-2024-11169?
To fix CVE-2024-11169, update the librechat software to the latest version that includes patches for this vulnerability.
Who is affected by CVE-2024-11169?
CVE-2024-11169 affects users running librechat version 3c94ff2, particularly those using the fs module for file uploads.
What causes the vulnerability in CVE-2024-11169?
The vulnerability in CVE-2024-11169 is caused by an unhandled exception in the fs module during file upload operations.
Can CVE-2024-11169 be exploited remotely?
Yes, an unauthenticated user can exploit CVE-2024-11169 remotely by sending a specially crafted request to the server.