漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Vulnerability Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
LiteLLM 授权问题漏洞
Vulnerability Description
LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.84.0之前版本存在授权问题漏洞,该漏洞源于MCP Streamable HTTP端点允许未经身份验证的攻击者使用伪造的Authorization标头触发OAuth2直通回退路径,导致LiteLLM密钥验证失败并返回空的UserAPIKeyAuth()对象,从而允许无有效密钥的请求访问MCP工具。
CVSS Information
N/A
Vulnerability Type
N/A