CVE-2024-4889 is a high-severity code injection vulnerability affecting berriai/litellm version 1.34.6. It allows authenticated attackers to achieve full system control by manipulating the UI_LOGO_PATH variable and injecting malicious code into the Google KMS configuration, which is then executed via the eval function. This vulnerability has a CVSS score of 7.2, indicating high impact on confidentiality, integrity, and availability, but requires high privileges and a specific Google KMS setup to exploit. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.44.16CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.