Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6847 | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9. |
Github GHSA |
GHSA-g5pg-73fc-hjwq | LiteLLM Reveals Portion of API Key via a Logging File |
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litellm
Litellm litellm |
|
| Weaknesses | CWE-116 | |
| CPEs | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Litellm
Litellm litellm |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9. | |
| Title | Improper Output Neutralization for Logs in berriai/litellm | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:55:27.073Z
Reserved: 2024-10-07T21:32:43.479Z
Link: CVE-2024-9606
No data.
Status : Analyzed
Published: 2025-03-20T10:15:49.443
Modified: 2025-04-07T14:50:05.277
Link: CVE-2024-9606
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA