A high-severity vulnerability with a CVSS score of 9.0 affects vllm versions less than 0.28.0 in OpenAI Chat Completion, allowing attackers to read arbitrary files through an insecure direct object reference (IDOR) flaw. This vulnerability can be exploited via the environment template management API by sending a crafted request, potentially leading to business impact due to unauthorized access to sensitive data and causing financial loss or reputational damage. The attack vector is network-based, as it involves sending a malicious request to the affected system. To mitigate this issue, a fix has been proposed in a public pull request, which includes changes to the serving.py file to handle errors more securely and the file to discard sender cache items properly.
We recommend you to update vllm to version 0.28.0.[/subscribe_to_unlock_form]
A high-severity vulnerability with a CVSS score of 9.0 affects vllm versions less than 0.28.0 in OpenAI Chat Completion, allowing attackers to read arbitrary files through an insecure direct object reference (IDOR) flaw. This vulnerability can be exploited via the environment template management API by sending a crafted request, potentially leading to business impact due to unauthorized access to sensitive data and causing financial loss or reputational damage. The attack vector is network-based, as it involves sending a malicious request to the affected system. To mitigate this issue, a fix has been proposed in a public pull request, which includes changes to the serving.py file to handle errors more securely and the file to discard sender cache items properly.
We recommend you to update vllm to version 0.28.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]