CVE-2024-10372

MEDIUM

chidiwilliams buzz <1.1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to insecure temporary file. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 4.5
EPSS 0.0007
EPSS Percentile 20.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-377
Status published
Products (1)
chidiwilliams/buzz 1.1.0
Published Oct 25, 2024
Tracked Since Feb 18, 2026