S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 25, 2024

CVE-2024-7340 Scanner

CVE-2024-7340 scanner - Arbitrary File Read vulnerability in W&B Weave Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7340
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
0
weaveby weights_\&_biases
0
Updated Aug 22, 2026View on NVD →
Detail

W&B Weave Server is a software component used primarily by data scientists and machine learning engineers for managing experiments and visualizing data workflows. It is commonly integrated with the W&B platform to track and manage the lifecycle of machine learning models. The software enables easy collaboration on projects and efficient handling of large-scale data. Due to its role in model management, maintaining its security is crucial for preventing unauthorized access to sensitive data.

The Arbitrary File Read vulnerability in W&B Weave Server allows an attacker to access files on the server through the Weave server API. This vulnerability can be exploited by traversing directories, thereby allowing unauthorized access to potentially sensitive files. Without proper input validation, a low-privileged user can leverage this flaw to read files outside the intended directory. If exploited, this vulnerability could lead to significant information disclosure and potential privilege escalation.

The W&B Weave Server exposes an endpoint that allows fetching files from a specific directory, intended for legitimate operations. However, due to insufficient input validation, an attacker can exploit path traversal techniques to access arbitrary files on the server, including sensitive configuration files. The vulnerable endpoint is the /__weave/file/tmp/weave/fs/ API, where an attacker can append directory traversal sequences like ../../../ to bypass restrictions. The server responds with the requested file, allowing the attacker to leak files such as /etc/passwd by manipulating the file path in the request.

Exploiting this vulnerability can lead to unauthorized access to sensitive files, including system and application configuration files. This information can be used to further compromise the server or escalate privileges. In severe cases, it may allow an attacker to gain administrative access or control over the server, leading to a broader security breach within the affected environment.

By using the S4E platform, you gain access to a comprehensive suite of tools designed to detect and manage vulnerabilities like the one affecting W&B Weave Server. Our platform continuously scans your digital assets for potential threats, providing timely alerts and actionable insights to mitigate risks. With automated updates and a user-friendly interface, S4E ensures that you stay ahead of emerging vulnerabilities, safeguarding your infrastructure and data from potential exploitation.

References:

Solution Advice
  • Update W&B Weave Server to the latest version where this vulnerability has been patched.
  • Implement strict input validation on file paths to prevent directory traversal.
  • Restrict access to the Weave server API to trusted users only.
  • Regularly monitor and audit server logs for unauthorized access attempts.
  • Consider deploying a Web Application Firewall (WAF) to filter and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.