Логотип exploitDog
bind:CVE-2024-12537
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12537

Количество 2

Количество 2

nvd логотип

CVE-2024-12537

11 месяцев назад

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-chf7-q7m5-fq92

11 месяцев назад

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-12537

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-chf7-q7m5-fq92

Open WebUI Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
1%
Низкий
11 месяцев назад

Уязвимостей на страницу