GHSA-m76r-xqqj-mqmv

Suggest an improvement
Source
https://github.com/advisories/GHSA-m76r-xqqj-mqmv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-m76r-xqqj-mqmv
Aliases
  • CVE-2024-9229
Published
2025-03-20T12:32:50Z
Modified
2025-03-21T03:53:46.916243Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Quivr unauthenticated Denial of Service (DoS) via Multipart Boundary
Details

A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated attackers to cause excessive resource consumption by appending characters to the end of a multipart boundary in an HTTP request. This leads to the server continuously processing each character, rendering the service unavailable and impacting all users.

Database specific
{
    "nvd_published_at": "2025-03-20T10:15:47Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-21T03:26:29Z"
}
References

Affected packages

PyPI / quivr-core

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.0.14

Affected versions

0.*

0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14