Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-9309

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or access unauthorized web resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.4%
CVSS Severity
CVSS v3 Score 9.3
Products affected by CVE-2024-9309
  • Hliu » Llava » Version: 1.2.0
    cpe:2.3:a:hliu:llava:1.2.0


Contact Us

Shodan ® - All rights reserved