CVE-2024-9340

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-9340 is a Denial of Service (DoS) vulnerability affecting zenml-io/zenml version 0.66.0. Unauthenticated attackers can exploit this flaw by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. The vulnerability results in an infinite loop, causing excessive resource consumption and a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`. This issue stems from a flaw in the multipart request boundary processing mechanism within the software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share