Логотип exploitDog
bind:CVE-2024-7049
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7049

Количество 2

Количество 2

nvd логотип

CVE-2024-7049

больше 1 года назад

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-947m-jhcv-94rp

больше 1 года назад

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7049

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-947m-jhcv-94rp

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу