Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vf8-xgwm-97r8

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Open WebUI lacks authentication for the api/v1/utils/pdf endpoint

In version v0.3.10 of open-webui/open-webui, the api/v1/utils/pdf endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.

Пакеты

Наименование

open-webui

pip
Затронутые версииВерсия исправления

<= 0.3.10

Отсутствует

EPSS

Процентиль: 73%
0.00782
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 8.2
nvd
11 месяцев назад

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.

EPSS

Процентиль: 73%
0.00782
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306