{ "id": "CVE-2024-11173", "sourceIdentifier": "security@huntr.dev", "published": "2025-03-20T10:15:24.663", "lastModified": "2025-03-20T10:15:24.663", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this vulnerability, LibreChat allows open registration, enabling unauthenticated attackers to create an account and perform the attack. The issue is fixed in version 0.7.6." }, { "lang": "es", "value": "Una excepci\u00f3n no controlada en el repositorio danny-avila/librechat, versi\u00f3n git 600d217, puede provocar un fallo del servidor, lo que resulta en una denegaci\u00f3n de servicio total. Este problema ocurre cuando ciertos endpoints de la API reciben una entrada mal formada, lo que resulta en una excepci\u00f3n no detectada. Aunque se requiere un JWT v\u00e1lido para explotar esta vulnerabilidad, LibreChat permite el registro abierto, lo que permite a atacantes no autenticados crear una cuenta y ejecutar el ataque. El problema est\u00e1 corregido en la versi\u00f3n 0.7.6." } ], "metrics": { "cvssMetricV30": [ { "source": "security@huntr.dev", "type": "Secondary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "security@huntr.dev", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-248" } ] } ], "references": [ { "url": "https://github.com/danny-avila/librechat/commit/95a212534f1c5991bd1231a34ac3668b4b592cc3", "source": "security@huntr.dev" }, { "url": "https://huntr.com/bounties/4cebf926-c17f-4836-868b-e1de86221cec", "source": "security@huntr.dev" } ] }