CRITICAL🇵🇱 Wersja polska

CVE-2024-6037

CVSS 9.1v3.1pub. 2024-07-10upd. 2025-10-15

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.

🤖 AI Analysis
How it works

An attacker, without the need for authentication, can send network requests that cause arbitrary folders to be created anywhere in the server's file system — including the root directory (e.g., C:\). Lack of proper control over resource creation (CWE-770) allows uncontrolled consumption of system resources. Mass creation of folders can lead to exhaustion of available disk space or file system limits, resulting in denial of service (DoS).

Impact

An attacker can cause server resource exhaustion, unavailability (DoS), and potential data loss or corruption. It is also possible to disrupt the integrity of the file system structure by writing to critical locations.

Mitigation & patch

The application should be updated to a version containing the patch available in the manufacturer's repository (commit 71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 on GitHub). Patches available from the manufacturer should be applied according to the references.

Who is affected

ChuanhuChatGPT (gaizhenbiao/chuanhuchatgpt) in version 20240410

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Gaizhenbiao Chuanhuchatgpt

    APP
    Gaizhenbiao
    20240410
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2024-5982CRITICAL9.8PL ✓same product

Path Traversal i RCE w ChuanhuChatGPT — niezabezpieczone dane wejściowe

CVE-2024-5823CRITICAL9.1PL ✓same product

Nadpisanie plików konfiguracyjnych w ChuanhuChatGPT (file overwrite)

CVE-2024-6036CRITICAL9.1PL ✓same product

Nieautoryzowany restart serwera w ChuanhuChatGPT poprzez endpoint /queue/join

CVE-2024-5822CRITICAL9.8PL ✓same product

SSRF w interfejsie upload ChuanhuChatGPT — dostęp do zasobów wewnętrznych

CVE-2024-3234CRITICAL9.8PL ✓same product

Path traversal w ChuanhuChatGPT — dostęp do poufnych plików