First published: Tue Apr 16 2024(Updated: )
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open WebUI | <0.1.117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30256 is classified as a moderate severity vulnerability involving authenticated blind server-side request forgery.
CVE-2024-30256 affects versions of Open WebUI prior to 0.1.117.
To fix CVE-2024-30256, upgrade Open WebUI to version 0.1.117 or later.
CVE-2024-30256 is an authenticated blind server-side request forgery vulnerability.
Exploitation of CVE-2024-30256 requires authentication, which may limit its potential impact depending on access policies.