CVE-2024-12068

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 918

Summary

CVE-2024-12068 is a Server-Side Request Forgery (SSRF) vulnerability discovered in the haotian-liu/llava library, specifically in version git c121f04. This issue allows malicious actors to manipulate the server into making HTTP requests to URLs of their choice. By exploiting this vulnerability, attackers can potentially gain unauthorized access to sensitive data, such as AWS metadata credentials, that is typically restricted to the server alone. This vulnerability poses a significant risk to systems using the affected version of llava and highlights the importance of keeping software up-to-date to mitigate security threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share