PT-2024-27145 · Oneflow · Oneflow

CVE-2024-36737

·

Published

2024-06-06

·

Updated

2025-05-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oneflow version 0.9.1
Description The issue is related to improper input validation, allowing attackers to cause a Denial of Service (DoS) by inputting a negative value into the oneflow.full parameter.
Recommendations For version 0.9.1, avoid using negative values in the oneflow.full parameter to prevent Denial of Service attacks. As a temporary workaround, consider validating user input to ensure it does not contain negative values.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-36737

Affected Products

Oneflow