Описание
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.
A flaw was found in LiteLLM. A user with access to the /user/update endpoint can exploit a privilege escalation vulnerability. By modifying their own user_role to proxy_admin, an attacker can gain full administrative access to LiteLLM, including control over all users, teams, keys, models, and prompt history.
Отчет
This vulnerability is rated Important because an authenticated LiteLLM proxy user may be able to modify their own user_role via the /user/update endpoint and escalate to proxy_admin, gaining full administrative access to the LiteLLM instance. Exploitation requires network access to a LiteLLM proxy deployment and valid credentials for a user who can reach the user management endpoints. Users with the org_admin role can exploit this directly. Products that bundle litellm without exposing the proxy user-management API have reduced exposure. Affected packages should be updated to litellm 1.83.10 or later when fixes are released.
Меры по смягчению последствий
Update the litellm package to version 1.83.10 or later. Until updated builds are available, restrict access to LiteLLM proxy /user/update and /user/bulk_update endpoints so only trusted administrators can modify user accounts. Audit user_role assignments for unexpected proxy_admin promotions.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-chatbot-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-chatbot-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
Уязвимость функции user_role прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером
EPSS
8.8 High
CVSS3