Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r4h-4cvr-v48c

Опубликовано: 04 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 2.6

Описание

A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.3.0 is able to address this issue. It is recommended to upgrade the affected component.

A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.3.0 is able to address this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 20%
0.00063
Низкий

2.1 Low

CVSS4

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
nvd
11 месяцев назад

A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.3.0 is able to address this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 20%
0.00063
Низкий

2.1 Low

CVSS4

2.6 Low

CVSS3