CVE-2024-0436
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.48%
- CWE
- CWE-203
- Published
- 2024-02-25
- Last modified
- 2026-03-13
Affected products
- mintplex-labs mintplex-labs/anything-llm
Weakness type
Related vulnerabilities
- CVE-2026-87459 — Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87620 — Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87619 — Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87566 — Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87623 — Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87518 — Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a...
- CVE-2026-87516 — Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87539 — Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...