CVE-2024-10906

CVSS 3.0 Score 7.1 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 352

Summary

CVE-2024-10906: In the 0.6.0 release of eosphoros-ai/db-gpt, an overly permissive CORS policy has been identified in the `uvicorn` application created by `dbgpt_server`. This misconfiguration sets the `Access-Control-Allow-Origin` header to `*`, making all server endpoints susceptible to Cross-Site Request Forgery (CSRF) attacks. An adversary can leverage this vulnerability to manipulate any endpoints of an affected instance, regardless of its network exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share