logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-7049

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-7049

Description:
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
Last updated date:
10/17/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/17/2024
Reference url to background

https://huntr.com/bounties/ee9e3532-8ef1-4599-bb59-b8e2ba43a1fc

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy