CVE-2024-10044 Information

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat as of commit e208d5677c6837d590b81cb03847c0b9de100765. This vulnerability allows attackers to exploit the victim controller API server’s credentials to perform unauthorized web actions or access unauthorized web resources by combining it with the POST /register_worker endpoint.

Reference

https://huntr.com/bounties/44633540-377d-4ac4-b3a3-c2d0fa19d0e6

Share on: