PT-2024-38040 · Unknown · Open-Webui

Published

2024-10-09

·

Updated

2024-11-03

·

CVE-2024-7038

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions open-webui version 0.3.8
Description An information disclosure issue exists related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
Recommendations For open-webui version 0.3.8, consider restricting access to the admin settings and the embedding model update feature until a patch is available. As a temporary workaround, consider modifying the error messages to be more generic, preventing attackers from enumerating file names and traversing directories.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-7038
GHSA-MQ92-JR35-FFPC

Affected Products

Open-Webui