CVE-2024-9308
CVSS 3.0 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-9308 is a newly disclosed open redirect vulnerability affecting version v1.2.0 of the haotian-liu/llava library, also known as LLaVA-1.6. This issue enables unauthenticated attackers to manipulate URLs and redirect unsuspecting users to malicious websites. The consequences can be severe, including phishing scams, malware distribution, and potential credential theft. The vulnerability poses a significant risk, particularly in web applications that rely on the affected library for input validation. Users are strongly encouraged to upgrade to a patched version as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LLaVA