A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata credentials.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hliu
Hliu llava |
|
| CPEs | cpe:2.3:a:hliu:llava:2024-05-11:*:*:*:*:*:*:* | |
| Vendors & Products |
Hliu
Hliu llava |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata credentials. | |
| Title | Server-Side Request Forgery in haotian-liu/llava | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:08:58.246Z
Updated: 2025-03-20T19:00:08.678Z
Reserved: 2024-12-02T21:29:51.931Z
Link: CVE-2024-12068
Updated: 2025-03-20T17:54:28.175Z
Status : Analyzed
Published: 2025-03-20T10:15:27.000
Modified: 2025-10-21T14:46:49.460
Link: CVE-2024-12068
No data.