Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48050 | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process. |
Thu, 17 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| Metrics |
cvssV3_1
|
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| CPEs | cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-webui
Open-webui open-webui |
|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process. | |
| Title | Exposure of Token in open-webui/open-webui | |
| Weaknesses | CWE-488 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-10-10T14:45:15.962Z
Reserved: 2024-07-23T19:15:08.148Z
Link: CVE-2024-7049
Updated: 2024-10-10T14:24:52.828Z
Status : Analyzed
Published: 2024-10-10T08:15:03.910
Modified: 2024-10-17T14:22:44.653
Link: CVE-2024-7049
No data.
OpenCVE Enrichment
No data.
EUVD