脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
脆弱性説明
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without any authentication.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
脆弱性タイプ
关键功能的认证机制缺失
脆弱性タイトル
GPUStack 授权问题漏洞
脆弱性説明
GPUStack GPUStack是GPUStack团队的一个管理GPU资源的服务器软件。 GPUStack 2.2.1及之前版本存在授权问题漏洞,该漏洞源于未受保护的/serveLogs和/debug端点,可能导致未经身份验证的攻击者访问敏感推理日志、修改worker配置、枚举模型实例ID以流式传输包含提示和完成的日志、更改日志级别及读取内存剖析数据。
CVSS情報
N/A
脆弱性タイプ
N/A