LlamaIndex 0.8.21

CPE Details

LlamaIndex 0.8.21
0.8.21
2024-01-29
11h25 +00:00
2024-01-29
11h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:llamaindex:llamaindex:0.8.21:*:*:*:*:*:*:*

Informations

Vendor

llamaindex

Product

llamaindex

Version

0.8.21

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-12910 2025-03-20 10h09 +00:00 A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the `get_article_urls` method, exhausting system resources and potentially crashing the application.
5.9
Medium
CVE-2024-23751 2024-01-22 00h00 +00:00 LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able to delete this year's student records via "Drop the Students table" within English language input.
9.8
Critical