CVE-2024-12070
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-12070 is a Denial of Service (DoS) vulnerability affecting the file upload feature in version 1.2.0 (LLaVA-1.6) of the haotian-liu/llava project. The issue arises due to the software's inability to handle filenames of excessive length in file upload requests. By exploiting this, an attacker can send a payload with an oversized filename, causing the server to become overwhelmed and unresponsive, resulting in unavailability for legitimate users. This vulnerability can be exploited without authentication, increasing the risk and potential scalability of attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LLaVA