Описание
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and ydoc:document:leave Socket.IO handlers accepted collaborative-document events without requiring an authenticated user, allowing unauthorized manipulation of document collaboration state. This issue is fixed in version 0.10.0.
Ссылки
- Patch
- Issue TrackingPatch
- ProductRelease Notes
- ExploitMitigationVendor Advisory
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.6.16 (включая) до 0.10.0 (исключая)
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00222
Низкий
3.1 Low
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 3.1
github
около 1 месяца назад
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
EPSS
Процентиль: 13%
0.00222
Низкий
3.1 Low
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-306