Medium severity5.9NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-7010
CVE-2024-7010
Description
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*
- (no CPE)range: <2.17.1
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/mudler/localai/commit/db1159b6511e8fa09e594f9db0fec6ab4e142468nvdPatch
- huntr.com/bounties/e286ed00-6383-47de-b5bc-9b9fad67c362nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.