CVE-2023-38976High· 7.5▾ TwilightWeaviate denial of service vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.1%
This vulnerability is a type conversion issue that affects users of Weaviate Server versions 1.20.0 and earlier. Who is impacted: Users of Weaviate Server versions 1.20.0 and earlier are impacted by this vulnerability.
A patch has been developed for this vulnerability. Patch releases 1.20.6, 1.19.13, and 1.18.6 are fixing this vulnerability in each respective minor version release. Users are strongly recommended to upgrade to one of these patched versions to address the vulnerability. Keeping software up-to-date is crucial to avoid security vulnerabilities.
There are no known workarounds to fix or remediate this vulnerability without upgrading. Users must upgrade to a patched version to mitigate the risk.
github.com/weaviate/weaviate >= 1.20.0, < 1.20.6github.com/weaviate/weaviate >= 1.19.0, < 1.19.13github.com/weaviate/weaviate < 1.18.6Upgrade to a patched release:
github.com/weaviate/weaviate 1.20.6github.com/weaviate/weaviate 1.19.13github.com/weaviate/weaviate 1.18.6Connected by shared product, vendor, weakness, or advisory.