CVE-2024-9229: Denial of Service (DoS) via Multipart Boundary in stangirard/quivr
A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated attackers to cause excessive resource consumption by appending characters to the end of a multipart boundary in an HTTP request. This leads to the server continuously processing each character, rendering the service unavailable and impacting all users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9229?
CVE-2024-9229 has been classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2024-9229?
To fix CVE-2024-9229, ensure that the file upload feature is properly validated and limited to mitigate excessive resource consumption.
Who is affected by CVE-2024-9229?
CVE-2024-9229 affects users of stangirard/quivr version 0.0.298 and the quivr-core package up to version 0.0.14.
What type of attack does CVE-2024-9229 facilitate?
CVE-2024-9229 facilitates a Denial of Service (DoS) attack by allowing unauthenticated attackers to cause excessive resource consumption.
In what component of the software does CVE-2024-9229 occur?
CVE-2024-9229 occurs in the file upload feature of the stangirard/quivr software.