CVE-2024-8982

CVSS 3.0 Score 6.2 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 29

Summary

CVE-2024-8982 is a Local File Inclusion (LFI) vulnerability affecting OpenLLM version 0.6.10. This issue enables attackers to include local files on the server through the web application, potentially exposing sensitive information such as configuration files, passwords, and private keys. Unauthorized access to critical server files, including user credentials (e.g., /etc/passwd) and private keys, can result in a complete compromise of the system's security. Attackers could exploit this vulnerability to further penetrate the network, exfiltrate data, or escalate privileges within the environment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share