ZeroHour

CVE-2024-12376

PoC
CVSS 3.0
7.5 high
EPSS
<1%p52
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.

Vendors
lm-sys
Products
fastchat
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.