Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-947m-jhcv-94rp

Опубликовано: 10 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

EPSS

Процентиль: 14%
0.00047
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-488

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

EPSS

Процентиль: 14%
0.00047
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-488