github.com
https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 CVE-2024-6037
CRITICAL
Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgpt
Record summary
CVE-2024-6037 has a selected CVSS score of 9.1 (critical).
Description
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
chuanhuchatgptBrowse gaizhenbiao / chuanhuchatgptDefault status: unknown | CVE List | 20240410 | affected |
gaizhenbiao/chuanhuchatgptBrowse gaizhenbiao / gaizhenbiao/chuanhuchatgpt | CVE List | Before 20240918 | affected |
References
3huntr.com
https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6037