CVE-2024-8982
CVSS 3.0 Score 6.2 of 10 (medium)
Details
Summary
CVE-2024-8982 is a Local File Inclusion (LFI) vulnerability affecting OpenLLM version 0.6.10. This issue enables attackers to include local files on the server through the web application, potentially exposing sensitive information such as configuration files, passwords, and private keys. Unauthorized access to critical server files, including user credentials (e.g., /etc/passwd) and private keys, can result in a complete compromise of the system's security. Attackers could exploit this vulnerability to further penetrate the network, exfiltrate data, or escalate privileges within the environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.