Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6707


Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.


Published

2024-08-07T23:15:41.457

Last Modified

2024-11-21T09:50:09.680

Status

Modified

Source

bbf0bd87-ece2-41be-b873-96928ee8fab9

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22
    CWE-434
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openwebui open_webui 0.1.105 Yes
Operating System debian debian_linux 12.0 No

References