RULE(RULE ID:338759)

Rule General Information
Release Date: 2025-03-26
Rule Name: Open WebUI Directory Traversal Vulnerability (CVE-2024-6707)
Severity:
CVE ID:
Rule Protection Details
Description: Open WebUI is an open-source, scalable, feature rich, and user-friendly self hosted WebUI. The Open WebUI version 0.1.105 has a security vulnerability that stems from being vulnerable to path traversal attacks, allowing attackers to upload controlled files to any location on the web server.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Refer to the announcement or patch by the vendor: https://github.com/open-webui/open-webui/releases/tag/v0.3.12