CVE-2024-5710: Improper Access Control in Team Management in berriai/litellm
berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member to or from any teams. The vulnerability stems from insufficient access control checks in various team management endpoints, enabling attackers to exploit these functionalities without proper authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.40.15
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5710?
CVE-2024-5710 has been classified as a high severity vulnerability due to its potential for unauthorized access and manipulation of team functionality.
How do I fix CVE-2024-5710?
To remediate CVE-2024-5710, upgrade to version 1.40.15 of the litellm package, which addresses the improper access control issue.
What actions can attackers perform due to CVE-2024-5710?
Attackers exploiting CVE-2024-5710 can create, update, view, delete, block, and unblock teams without proper authorization.
Which versions of litellm are affected by CVE-2024-5710?
CVE-2024-5710 specifically affects litellm version 1.34.34 and earlier versions.
Is there a patch available for CVE-2024-5710?
Yes, a patch is available in the latest version 1.40.15 of the litellm package.