Vulnerabilities > CVE-2024-0436 - Unspecified vulnerability in Mintplexlabs Anythingllm 0.0.1/0.1.0

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
mintplexlabs

Summary

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute

Vulnerable Configurations

Part Description Count
Application
Mintplexlabs
3