PT-2025-12318 · Unknown · Berriai/Litellm
Published
2025-03-20
·
Updated
2025-03-23
·
CVE-2025-0628
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BerriAI/litellm version main-latest
Description
The issue is related to improper authorization. When a user with the role
internal user viewer logs into the application, they are provided with an overly privileged API key. This key allows access to all admin functionality, including endpoints such as "/users/list" and "/users/get users". The vulnerability enables privilege escalation within the application, allowing any account to become a proxy admin.Recommendations
For BerriAI/litellm version main-latest, consider restricting access to the
/users/list and /users/get users endpoints until a fix is available. As a temporary workaround, review and limit the privileges assigned to the internal user viewer role to prevent unauthorized access to admin functionality.Fix
LPE
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Berriai/Litellm