Логотип exploitDog
bind:CVE-2024-11603
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-11603

Количество 2

Количество 2

nvd логотип

CVE-2024-11603

11 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h254-g997-685c

11 месяцев назад

FastChat Server-Side Request Forgery vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-11603

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-h254-g997-685c

FastChat Server-Side Request Forgery vulnerability

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу