Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-7340 PoC — Weave 安全漏洞

Source
Associated Vulnerability
Title:Weave 安全漏洞 (CVE-2024-7340)
Description:Weave是Weights & Biases开源的一个用于开发生成式人工智能应用程序的工具包。 Weave存在安全漏洞,该漏洞源于API允许远程用户从特定目录中获取文件,从而导致远程遍历和泄露任意文件。
Description
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
File Snapshot

id: CVE-2024-7340 info: name: W&B Weave Server - Remote Arbitrary File Leak author: iamnoooob,r ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.