LiteLLM 存在一个弱的认证漏洞,允许持有由配置的身份提供商签发的有效 JWT(JSON Web Token)的攻击者,通过在 JWT 认证流程中利用基于电子邮件的回退查找机制(该机制未验证 声明),以任意现有用户的身份进行认证。攻击者可以提交一个包含未验证电子邮件地址的令牌,该地址与目标用户的账户电子邮件相匹配,从而继承该目标用户的角色权限,包括 管理员权限。此攻击还会永久覆盖目标用户存储的身份绑定信息,使攻击者能够持续未授权地访问暴露 API 密钥和用户管理功能的后台管理接口。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet