VDB
CVE-2024-6587
CVE-2024-6587
PUBLISHED
KEV
CVSS 7.5 HIGH
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
EPSS 35.32% · 98.4th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
35.32%
98.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| litellm | litellm | 1.38.10, 1.38.10 |
| PyPI | litellm | 0, 0 |
| berriai | litellm | 0, 0 |
| berriai | berriai/litellm | *, * |
Timeline
- Jul 22, 2024 Nuclei Template
- Jul 22, 2024 Fix Commit
- Aug 22, 2024 VulnCheck KEV Exploitation
- Aug 25, 2024 VulnCheck KEV Exploitation
- Aug 26, 2024 VulnCheck KEV Exploitation
- Aug 28, 2024 VulnCheck KEV Exploitation
- Sep 4, 2024 VulnCheck KEV Exploitation
- Sep 8, 2024 VulnCheck KEV Exploitation
- Sep 13, 2024 CVE Published
- Sep 14, 2024 EPSS Score
- Sep 16, 2024 VulnCheck KEV Exploitation
- Sep 17, 2024 VulnCheck KEV Exploitation