Описание
Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.
Ссылки
EPSS
Процентиль: 38%
0.00454
Низкий
5 Medium
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5
github
2 месяца назад
Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.
EPSS
Процентиль: 38%
0.00454
Низкий
5 Medium
CVSS3
Дефекты
CWE-918