berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member to or from any teams. The vulnerability stems from insufficient access control checks in various team management endpoints, enabling attackers to exploit these functionalities without proper authorization.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Litellm
Litellm litellm |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:litellm:litellm:1.34.34:*:*:*:*:*:*:* | |
Vendors & Products |
Litellm
Litellm litellm |
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-27T18:41:19.900Z
Updated: 2024-08-01T21:18:07.053Z
Reserved: 2024-06-06T18:20:46.162Z
Link: CVE-2024-5710
Vulnrichment
Updated: 2024-08-01T21:18:07.053Z
NVD
Status : Modified
Published: 2024-06-27T19:15:15.667
Modified: 2024-11-21T09:48:12.877
Link: CVE-2024-5710
Redhat
No data.