CVE-2024-5710

Source
https://cve.org/CVERecord?id=CVE-2024-5710
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5710.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5710
Aliases
Published
2024-06-27T18:41:19.900Z
Modified
2026-07-15T01:49:03.724862263Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Improper Access Control in Team Management in berriai/litellm
Details

berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member to or from any teams. The vulnerability stems from insufficient access control checks in various team management endpoints, enabling attackers to exploit these functionalities without proper authorization.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5710.json"
}
References

Affected packages

Git / github.com/berriai/litellm

Affected ranges

Type
GIT
Repo
https://github.com/berriai/litellm
Events
Database specific
{
    "cpe": "cpe:2.3:a:litellm:litellm:1.34.34:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.34.34"
        },
        {
            "last_affected": "1.34.34"
        }
    ]
}

Affected versions

1.*
1.34.34
v1.*
v1.34.34

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5710.json"