VDB
EN
HIGH

GHSA-53mr-6c8q-9789

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

상세

### Impact

The `/config/update endpoint` does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:

- Modify proxy configuration and environment variables - Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution - Read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image - Take over other priveleged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables

### Patches

Fixed in v1.83.0. The endpoint now requires `proxy_admin` role.

### Workarounds

Restrict API key distribution. There is no configuration-level workaround.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / litellm
최초 영향 버전: 0 수정 버전: 1.83.0
수정 pip install --upgrade 'litellm>=1.83.0'

참고