CVE-2024-10906 affects version 0.6.0 of eosphoros-ai/db-gpt, where the dbgpt_server's uvicorn app uses an overly permissive CORSMiddleware configuration. This misconfiguration sets "Access-Control-Allow-Origin" to "*" for all requests, making all server endpoints vulnerable to Cross-Site Request Forgery (CSRF). With a CVSS score of 8.1 (HIGH), this vulnerability allows an unauthenticated attacker to interact with any server endpoint, potentially leading to high impact on integrity and availability, even if the instance is not publicly exposed. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.0CPE matchmatch criteria | cpe:2.3:a:dbgpt:db-gpt:0.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.