CVE-2024-10649

CVSS 3.0 Score 6.1 of 10 (medium)

Details

Published Feb 10, 2025
Updated: Feb 11, 2025
CWE ID 306

Summary

CVE-2024-10649 is a newly identified vulnerability in wandb/openui where unauthenticated endpoints enable file uploads and downloads from an Amazon S3 bucket. This weakness could lead to denial-of-service attacks, stored Cross-Site Scripting (XSS), and information disclosure. The affected endpoints are '/v1/share/{id:str}' for file uploads and '/v1/share/{id:str}' for JSON file downloads. The absence of authentication allows any user to upload and overwrite files, risking S3 bucket exhaustion and data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share