Description

An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.

INFO

Published Date :

2024-10-09T18:26:38.995Z

Last Modified :

2024-11-03T18:27:26.279Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7038 vulnerability.

Vendors Products
Openwebui
  • Open Webui
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7038.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact