Vulnerability Description
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | 0.3.8 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/ee9e3532-8ef1-4599-bb59-b8e2ba43a1fcExploitThird Party Advisory
FAQ
What is CVE-2024-7049?
CVE-2024-7049 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation...
How severe is CVE-2024-7049?
CVE-2024-7049 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7049?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.