CVE-2024-7010

Source
https://cve.org/CVERecord?id=CVE-2024-7010
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7010.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7010
Published
2024-10-29T12:48:29.287Z
Modified
2026-07-15T01:49:14.464940862Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Timing Attack in mudler/localai
Details

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7010.json",
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-208"
    ]
}
References

Affected packages

Git / github.com/mudler/localai

Affected ranges

Type
GIT
Repo
https://github.com/mudler/localai
Events
Database specific
{
    "cpe": "cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.17.1"
        },
        {
            "last_affected": "2.17.1"
        }
    ]
}

Affected versions

2.*
2.17.1
v2.*
v2.17.1
v2.18.0
v2.18.1
v2.19.0
v2.19.1
v2.19.2
v2.19.3
v2.19.4
v2.20.0
v2.20.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7010.json"