Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.
References
Link | Resource |
---|---|
https://korelogic.com/Resources/Advisories/KL-001-2024-006.txt | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Aug/4 | |
http://www.openwall.com/lists/oss-security/2024/08/08/7 |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-08-07 23:15
Updated : 2024-11-21 09:50
NVD link : CVE-2024-6707
Mitre link : CVE-2024-6707
CVE.ORG link : CVE-2024-6707
JSON object : View
Products Affected
openwebui
- open_webui
debian
- debian_linux