CVE-2024-9340
ZenML unauthenticated DoS via Multipart Boundry
7.5
HIGH
CVSS 3.1
EPSS 0.22%
Description
A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`.
How to fix CVE-2024-9340
To remediate CVE-2024-9340, upgrade the affected package to a fixed version below.
- —upgrade to 0.68.0 or later
- —upgrade to cba152eb9ca3071c8372b0b91c02d9d3351de48d or later
Is CVE-2024-9340 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.68.0
- from 0, < cba152eb9ca3071c8372b0b91c02d9d3351de48d | from 0, < 0.68.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |