PT-2024-38040 · Unknown · Open-Webui
Published
2024-10-09
·
Updated
2024-11-03
·
CVE-2024-7038
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
open-webui version 0.3.8
Description
An information disclosure issue exists related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
Recommendations
For open-webui version 0.3.8, consider restricting access to the admin settings and the embedding model update feature until a patch is available. As a temporary workaround, consider modifying the error messages to be more generic, preventing attackers from enumerating file names and traversing directories.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui