Aller au contenu

Fiche vulnérabilité

CVE-2024-10906 : faille élevée dbgpt db-gpt (CVSS 8.1)

Description

In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • dbgpt db-gpt

Références

Rechercher une autre vulnérabilité dans la base CVE