Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12799

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

A flaw was found in BerriAI litellm. A remote attacker could exploit an improper authorization vulnerability in the ui_view_users function to gain access to sensitive information. This issue is related to an incomplete fix for a previous vulnerability.

Отчет

This Moderate impact vulnerability in BerriAI litellm allows a remote attacker to access sensitive user information due to an improper authorization flaw within the ui_view_users function.

Меры по смягчению последствий

To reduce exposure, restrict network access. Configure firewall rules to permit connections only from trusted hosts or networks to the port used by the litellm proxy. If the management interface is not essential for operations, consider disabling the service or removing the affected component. Any changes to network configurations or service states may require a restart or reload of the affected service to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2491141litellm: BerriAI litellm: Information Disclosure via improper authorization in ui_view_users function

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

CVSS3: 4.3
github
около 2 месяцев назад

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3