OpenSift Race Condition Vulnerability in Local JSON Persistence
Vulnerability
A race condition vulnerability has been identified in OpenSift, an AI study tool, in versions prior to 1.1.3-alpha. The issue arises from non-atomic and poorly synchronized local JSON persistence processes, which can lead to concurrent operations overwriting updates or corrupting the local state across various stores, including sessions, study, quiz, flashcard, wellness, and authentication.
Impact
This vulnerability can cause state corruption or loss by allowing concurrent operations to interfere with each other, leading to lost updates or corrupted data in the affected stores.
Remediation
Users can upgrade to OpenSift version 1.1.3-alpha or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
