The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: JFROG
Published: 2024-07-31T15:00:04.218Z
Updated: 2024-07-31T16:13:32.666Z
Reserved: 2024-07-31T14:34:53.114Z
Link: CVE-2024-7340
Vulnrichment
Updated: 2024-07-31T16:07:44.136Z
NVD
Status : Awaiting Analysis
Published: 2024-07-31T15:15:11.203
Modified: 2024-08-01T14:01:07.677
Link: CVE-2024-7340
Redhat
No data.