SCA: security update for litellm (GHSA-qqcv-vg9f-5rr3)

medium Tenable Self-Hosted Container Security Plugin ID 418273

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management
functionality. This vulnerability allows attackers to perform unauthorized actions such as creating,
updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member
to or from any teams. The vulnerability stems from insufficient access control checks in various team
management endpoints, enabling attackers to exploit these functionalities without proper authorization.
(CVE-2024-5710)

Solution

Update the litellm library and its related packages to version 1.40.15 or later.

See Also

https://github.com/advisories/GHSA-qqcv-vg9f-5rr3

Plugin Details

Severity: Medium

ID: 418273

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2024-5710

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/27/2024

Vulnerability Publication Date: 6/27/2024

Reference Information

CVE: CVE-2024-5710