CVE-2024-7340 describes a path traversal vulnerability in the Weave server API, allowing remote attackers to leak arbitrary files due to insufficient input validation. This flaw can enable low-privileged users to escalate privileges to server administrator in common scenarios. With a CVSS score of 8.8 (High) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk, potentially leading to complete compromise of confidentiality, integrity, and availability. While not yet observed in active exploitation or listed on KEV, public Nuclei templates exist, suggesting a readily exploitable condition despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Https://Pypi.Org/Project/Pip | Weave | >= 0, <= 0.50.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.