In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dbgpt
Dbgpt db-gpt |
|
CPEs | cpe:2.3:a:dbgpt:db-gpt:0.6.0:*:*:*:*:*:*:* | |
Vendors & Products |
Dbgpt
Dbgpt db-gpt |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network. | |
Title | Cross-Site Request Forgery (CSRF) in eosphoros-ai/db-gpt | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:05.603Z
Updated: 2025-03-20T18:31:38.806Z
Reserved: 2024-11-05T21:41:10.336Z
Link: CVE-2024-10906

Updated: 2025-03-20T17:49:36.214Z

Status : Analyzed
Published: 2025-03-20T10:15:21.233
Modified: 2025-07-17T13:43:47.070
Link: CVE-2024-10906

No data.