CVE-2024-9340
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-9340 is a Denial of Service (DoS) vulnerability affecting zenml-io/zenml version 0.66.0. Unauthenticated attackers can exploit this flaw by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. The vulnerability results in an infinite loop, causing excessive resource consumption and a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`. This issue stems from a flaw in the multipart request boundary processing mechanism within the software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.