{"data":{"id":"80c68f99-d939-476e-9ba2-eeba300a0222","title":"GHSA-qqcv-vg9f-5rr3: litellm vulnerable to improper access control in team management","summary":"berriai/litellm version 1.34.34 has an improper access control flaw in its team management functionality. Insufficient access control checks in various team management endpoints let attackers create, update, view, delete, block, and unblock any team, and add or remove any team member, without authorization.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-qqcv-vg9f-5rr3","publishedAt":"2024-06-27T21:32:08.000Z","cveId":"CVE-2024-5710","cweIds":["CWE-284","CWE-862"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":["litellm@< 1.40.15 (fixed: 1.40.15)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00406,"epssCheckedAt":"2026-10-10T04:57:09.443Z","kevDateAdded":null,"advisoryAliases":["GHSA-qqcv-vg9f-5rr3"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2024-06-27T21:32:08.000Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}