漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthenticated File Upload in parisneo/lollms
Vulnerability Description
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
LoLLMs 授权问题漏洞
Vulnerability Description
LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言与多模态系统。 lollms 2.2.0及之前版本存在授权问题漏洞,该漏洞源于/api/files/extract-text端点未强制身份验证,可能导致拒绝服务、信息泄露和违反安全策略。
CVSS Information
N/A
Vulnerability Type
N/A