In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Litellm
Litellm litellm |
|
Weaknesses | CWE-116 | |
CPEs | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Litellm
Litellm litellm |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9. | |
Title | Improper Output Neutralization for Logs in berriai/litellm | |
Weaknesses | CWE-117 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:55:27.073Z
Reserved: 2024-10-07T21:32:43.479Z
Link: CVE-2024-9606

No data.

Status : Analyzed
Published: 2025-03-20T10:15:49.443
Modified: 2025-04-07T14:50:05.277
Link: CVE-2024-9606

No data.