HIGH
W&B Weave server remote arbitrary file leak and privilege escalation
Published Jul 31, 2024
8.7
HIGHCVSS 4.0
EPSS 5.01%
Description
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
Affected products
No data.
No data.
-
- Version 0StatusaffectedConstraints<=0.50.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Weights \& Biases | Weave | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2408 Advisory
- https://github.com/advisories/GHSA-r49h-6qxq-624f Advisory
- https://github.com/wandb/weave/commit/f43d5fb75e0d52933a52ecd9a0ce2f9b082e6c9f
- https://github.com/wandb/weave/pull/1657 patch
- https://nvd.nist.gov/vuln/detail/CVE-2024-7340
- https://research.jfrog.com/vulnerabilities/wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248 third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner JFROG
Published Jul 31, 2024
Updated Nov 25, 2024
Reserved Jul 31, 2024
Link CVE-2024-7340
CISA Vulnrichment
Updated Jul 31, 2024
ENISA EUVD
EUVD-2024-2408 GHSA-R49H-6QXQ-624F Assigner JFROG
Published Jul 31, 2024
Updated Nov 25, 2024
Exploited since n/a
Link EUVD-2024-2408