Server-Side Request Forgery Vulnerability in lm-sys/fastchat Web Server
CVE-2024-12376
7.5HIGH
Summary
A vulnerability exists in the lm-sys/fastchat web server that enables Server-Side Request Forgery (SSRF). This flaw permits attackers to manipulate server requests, allowing them to gain unauthorized access to sensitive internal resources, including AWS metadata credentials, which could lead to further exploitation and data breaches.
Affected Version(s)
lm-sys/fastchat <= unspecified
References
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved