Skip to content
LowVulnerabilityLLM-specific

GHSA-w2mh-qq9q-453x: BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

BerriAI litellm up to 1.82.2 contains a flaw in the get_redirect_response_from_openid function in litellm/proxy/management_endpoints/ui_sso.py, part of the SSO Authentication Flow component. Manipulating this flow leads to session expiration, and the attack can be carried out remotely. A public exploit is available and might be used. The vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.