CVE-2024-10906
Python 脆弱性の分析と軽減

概要

In version 0.6.0 of eosphoros-ai/db-gpt, a critical security vulnerability was identified involving the uvicorn app created by dbgpt_server. The vulnerability stems from an overly permissive instance of CORSMiddleware which sets the Access-Control-Allow-Origin to * for all requests. This vulnerability was assigned CVE-2024-10906 and was disclosed on March 20, 2025 (NVD).

技術的な詳細

The vulnerability is classified as a Cross-Site Request Forgery (CSRF) vulnerability with a CVSS v3.0 base score of 7.1 (HIGH). The technical root cause is the misconfiguration of CORS policy in the uvicorn app, where the Access-Control-Allow-Origin header is set to *, allowing requests from any origin. The vulnerability has been assigned CWE-352 (Cross-Site Request Forgery) classification (NVD, Huntr).

影響

The vulnerability makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can potentially interact with any endpoints of the instance, even if the instance is not publicly exposed to the network. This poses a significant risk as it could allow unauthorized actions to be performed on behalf of authenticated users (NVD).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 Python 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-47708CRITICAL9.3
  • Python logoPython
  • stata-mcp
いいえはいJul 21, 2026
CVE-2026-47731CRITICAL9.1
  • Python logoPython
  • ait-core
いいえはいJul 21, 2026
CVE-2026-63764HIGH7.7
  • Python logoPython
  • lmdeploy
いいえいいえJul 21, 2026
GHSA-rwj8-pgh3-r573HIGH7.5
  • Python logoPython
  • gitpython
いいえはいJul 21, 2026
CVE-2026-46556MEDIUM6.5
  • Python logoPython
  • flaskbb
いいえいいえJul 21, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者