An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
Metrics
Affected Vendors & Products
References
History
Sun, 03 Nov 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 |
Tue, 15 Oct 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-209 | |
CPEs | cpe:2.3:a:openwebui:open_webui:-:*:*:*:*:*:*:* | |
Metrics |
cvssV3_1
|
Wed, 09 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openwebui
Openwebui open Webui |
|
CPEs | cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openwebui
Openwebui open Webui |
|
Metrics |
ssvc
|
Wed, 09 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information. | |
Title | Information Disclosure in open-webui/open-webui | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-09T18:26:38.995Z
Updated: 2024-11-03T18:27:26.279Z
Reserved: 2024-07-23T17:52:31.731Z
Link: CVE-2024-7038
Vulnrichment
Updated: 2024-10-09T20:08:15.682Z
NVD
Status : Modified
Published: 2024-10-09T19:15:14.930
Modified: 2024-11-03T17:15:15.340
Link: CVE-2024-7038
Redhat
No data.