A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior knowledge of the username. Once the password is known, attackers can conduct blind attacks to ascertain the full username, significantly compromising system security.
Metrics
Affected Vendors & Products
References
History
Sun, 03 Nov 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-229 |
Sun, 03 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:mintplexlabs:anythingllm:-:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Tue, 22 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mintplexlabs
Mintplexlabs anythingllm |
|
Weaknesses | CWE-307 | |
CPEs | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mintplexlabs
Mintplexlabs anythingllm |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:19:23.450Z
Updated: 2024-11-03T18:27:23.547Z
Reserved: 2024-03-29T18:43:30.670Z
Link: CVE-2024-3102
Vulnrichment
Updated: 2024-08-01T19:32:42.847Z
NVD
Status : Modified
Published: 2024-06-06T19:15:59.667
Modified: 2024-11-21T09:28:54.413
Link: CVE-2024-3102
Redhat
No data.