berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member to or from any teams. The vulnerability stems from insufficient access control checks in various team management endpoints, enabling attackers to exploit these functionalities without proper authorization.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_0
|
Fri, 20 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litellm
Litellm litellm |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:litellm:litellm:1.34.34:*:*:*:*:*:*:* | |
| Vendors & Products |
Litellm
Litellm litellm |
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-27T18:41:19.900Z
Updated: 2025-10-15T12:49:43.063Z
Reserved: 2024-06-06T18:20:46.162Z
Link: CVE-2024-5710
Updated: 2024-08-01T21:18:07.053Z
Status : Modified
Published: 2024-06-27T19:15:15.667
Modified: 2025-10-15T13:15:47.237
Link: CVE-2024-5710
No data.