LiteLLM 게이트웨이의 10%가 기본 관리자 키인 'sk-1234'를 수용했다는 보고서.
Wiz Research가 탐지한 바에 따르면, 인터넷에 노출된 LiteLLM 서버 중 10%가 기본 관리자 키 'sk-1234'를 수용하고 있습니다. LiteLLM은 애플리케이션과 모델 공급자 간의 중개 역할을 하는 오픈소스 AI 게이트웨이입니다. 이 키는 게이트웨이의 관리자 자격 증명으로, 이를 소유한 사람은 모든 데이터를 읽을 수 있어 보안 위험이 발생합니다.
Nearly 10% of exposed LiteLLM gateways accepted the default admin key 'sk-1234'.
According to Wiz Research, nearly 10% of internet-facing LiteLLM servers accepted the default admin key 'sk-1234'. LiteLLM serves as an open-source AI gateway, acting as a liaison between applications and the model providers. This key is the administrator credential for the gateway, which poses a significant security risk as anyone holding it can access all data.