CVE-2024-10906: DB-GPT vulnerable to Cross-Site Request Forgery
(updated )
In version 0.6.0 of eosphoros-ai/db-gpt, the uvicorn
app created by dbgpt_server
uses an overly permissive instance of CORSMiddleware
which sets the Access-Control-Allow-Origin
to *
for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-10906 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →