Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4889

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 7.2
CVSS3: 7.2
EPSS Низкий

Описание

A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function within the secret management system. This vulnerability requires a valid Google KMS configuration file to be exploitable. Specifically, by setting the UI_LOGO_PATH variable to a remote server address in the get_image function, an attacker can write a malicious Google KMS configuration file to the cached_logo.jpg file. This file can then be used to execute arbitrary code by assigning malicious code to the SAVE_CONFIG_TO_DB environment variable, leading to full system control. The vulnerability is contingent upon the use of the Google KMS feature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Версия до 1.44.16 (исключая)

EPSS

Процентиль: 37%
0.00163
Низкий

7.2 High

CVSS3

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
github
больше 1 года назад

A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function within the secret management system. This vulnerability requires a valid Google KMS configuration file to be exploitable. Specifically, by setting the `UI_LOGO_PATH` variable to a remote server address in the `get_image` function, an attacker can write a malicious Google KMS configuration file to the `cached_logo.jpg` file. This file can then be used to execute arbitrary code by assigning malicious code to the `SAVE_CONFIG_TO_DB` environment variable, leading to full system control. The vulnerability is contingent upon the use of the Google KMS feature.

EPSS

Процентиль: 37%
0.00163
Низкий

7.2 High

CVSS3

7.2 High

CVSS3

Дефекты

CWE-94