privategpt Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in privategpt version 0.5.0. The issue arises when a file is uploaded and a large number of characters are appended to the end of the multipart boundary. This causes the system to continuously process the excess characters, leading to prolonged unavailability of the service. The excessive resource consumption can disrupt operations, cause data inaccessibility, and result in a loss of productivity. In testing, adding nearly 10 million characters rendered privategpt inaccessible for several hours.
Impact
Exploitation of this vulnerability causes a denial-of-service condition, making privategpt unavailable for an extended period. This disruption can lead to significant operational challenges, including data inaccessibility and decreased productivity.
Reproduction
To reproduce this vulnerability, upload a file to privategpt while intercepting the request with Burp Suite. Add a large number of characters after the multipart boundary and send the request. The privategpt service will become unavailable as it processes the excessive characters, leading to a denial-of-service condition.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
