Medium severity5.9NVD Advisory· Published Feb 26, 2024· Updated Jun 17, 2026
CVE-2024-0436
CVE-2024-0436
Description
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the !== used for comparison.
The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*range: <1.0.0
- (no CPE)
- mintplex-labs/mintplex-labs/anything-llmv5Range: unspecified
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.