Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial of Service in bentoml/bentoml
Vulnerability Description
BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.
CVSS Information
N/A
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
BentoML 资源管理错误漏洞
Vulnerability Description
BentoML是BentoML开源的一个开源模型服务库。用于使用 Python 构建高性能和可扩展的人工智能应用程序。 BentoML v1.3.4post1版本存在资源管理错误漏洞,该漏洞源于未正确处理多部分边界,可能导致拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A