High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-12068
CVE-2024-12068
Description
A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2git c121f04+ 1 more
- (no CPE)range: git c121f04
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/9d0b908d-63cd-4d62-91ff-6ceef3183752nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.