CVE-2024-9437: Unauthenticated Denial of Service in transformeroptimus/superagi
SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request causes the server to continuously process each character. This leads to excessive resource consumption and renders the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9437?
CVE-2024-9437 is rated as a high severity vulnerability due to its potential to cause an unauthenticated Denial of Service attack.
How do I fix CVE-2024-9437?
To mitigate CVE-2024-9437, it is recommended to update SuperAGI to a version that resolves the vulnerable resource upload request handling.
What type of attack does CVE-2024-9437 facilitate?
CVE-2024-9437 facilitates an unauthenticated Denial of Service attack by exploiting the multipart boundary in HTTP requests.
Which version of SuperAGI is affected by CVE-2024-9437?
CVE-2024-9437 affects SuperAGI version v0.0.14.
Can CVE-2024-9437 be exploited remotely?
Yes, CVE-2024-9437 can be exploited remotely, as it does not require authentication to carry out the Denial of Service attack.