Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j42-pcfm-3467

Опубликовано: 06 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

SQL injection in litellm

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit this vulnerability by injecting malicious SQL commands through the 'user_id' parameter, leading to potential unauthorized access to sensitive information such as API keys, user information, and tokens stored in the database. The affected version is 1.27.14.

Пакеты

Наименование

litellm

pip
Затронутые версииВерсия исправления

<= 1.27.14

Отсутствует

EPSS

Процентиль: 26%
0.00092
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 4.9
nvd
больше 1 года назад

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit this vulnerability by injecting malicious SQL commands through the 'user_id' parameter, leading to potential unauthorized access to sensitive information such as API keys, user information, and tokens stored in the database. The affected version is 1.27.14.

EPSS

Процентиль: 26%
0.00092
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-89