S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 2, 2024

CVE-2024-6587 Scanner

CVE-2024-6587 scanner - Server-Side Request Forgery (SSRF) vulnerability in LiteLLM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6587
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified by `api_base`. This request includes the OpenAI API key. A malicious user can set the `api_base` to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
berriai/litellmby berriai
AFFECTED< 1.44.9SAFE ✓≥ 1.44.9
litellmby berriai
AFFECTED< 1.44.9SAFE ✓≥ 1.44.9
Updated Sep 10, 2026View on NVD →
Detail

LiteLLM is a lightweight language model framework designed for integration with various AI tools and platforms. It is widely used by developers and AI researchers to interact with large language models like OpenAI's GPT-4. LiteLLM allows for easy deployment and interaction with AI models, particularly in environments where resources are limited. Its open-source nature and flexibility make it a popular choice for custom AI solution development. The software is typically employed in AI-driven applications, chatbots, and automation tools.

The SSRF vulnerability in LiteLLM allows an attacker to manipulate requests sent by the server. This can lead to unauthorized access to internal systems or expose sensitive information such as API keys. The flaw lies in the way the software handles URL inputs, allowing malicious actors to craft requests that the server then executes. The exploitation of this vulnerability can lead to severe security breaches, including unauthorized data access.

The vulnerability exists in the api_base parameter within the LiteLLM's HTTP request handling. When processing requests, LiteLLM fails to properly validate and sanitize this parameter, allowing attackers to inject arbitrary URLs. This can result in the server performing unintended actions, such as interacting with internal services or external servers. The vulnerability is particularly dangerous because it can be used to expose sensitive data, including OpenAI API keys, when an attacker controls the URL endpoint. The flaw is triggered when an attacker sends a specially crafted request that the server mistakenly trusts.

If exploited, the SSRF vulnerability can allow attackers to gain unauthorized access to internal network resources or services. This could lead to data exfiltration, system compromise, or even full control over certain server functions. Additionally, sensitive data such as API keys may be exposed, potentially leading to further exploitation, unauthorized API access, or misuse of AI capabilities.

By using the S4E platform, you can proactively identify and remediate critical vulnerabilities like SSRF in your systems. Our comprehensive scanning tools ensure your applications are secure against the latest threats, while our detailed reports guide you through remediation. Join our platform to stay ahead of potential exploits, protect your data, and maintain your system's integrity. Benefit from our continuous updates, expert insights, and a community-driven approach to cybersecurity.

References:

Solution Advice
  • Validate and sanitize all URL inputs to ensure they only allow trusted and safe endpoints.
  • Implement strict access controls on internal network resources to prevent unauthorized access.
  • Regularly update and patch software to mitigate known vulnerabilities.
  • Monitor network traffic for unusual patterns that could indicate an SSRF attack.
  • Conduct regular security assessments to identify and fix potential weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.