A vulnerability in gaizhenbiao/chuanhuchatgpt version...
High severity
Unreviewed
Published
Jul 11, 2024
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 10, 2024
Published to the GitHub Advisory Database
Jul 11, 2024
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the
/queue/join?
endpoint with"fn_index":66
. This unrestricted server restart capability can severely disrupt service availability, cause data loss or corruption, and potentially compromise system integrity.References