gist.github.com
https://gist.github.com/Redmept1on/3a77cc722f82b57f99ccbe835aacf27d CVE-2024-36737
HIGH
Record summary
CVE-2024-36737 has a selected CVSS score of 7.5 (high).
Description
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 20, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
oneflowBrowse oneflow / oneflowDefault status: unknown | CVE List | 0.9.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36737