MediumVulnerability
GHSA-qqcv-vg9f-5rr3: litellm vulnerable to improper access control in team management
- Identifiers
- CVE-2024-5710GHSA-qqcv-vg9f-5rr3
- Published
- Record updated
- Affected
- litellm < 1.40.15
- Fixed in
- 1.40.15
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
berriai/litellm version 1.34.34 has an improper access control flaw in its team management functionality. Insufficient access control checks in various team management endpoints let attackers create, update, view, delete, block, and unblock any team, and add or remove any team member, without authorization.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents