CVE-2024-7040: Improper Access Control in open-webui/open-webui
Published Mar 20, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
2 affected components
open-webui open-webui
openwebui Open WebUI=0.3.8
Event History
Mar 20, 2025
CVE Published
via MITRE·10:09 AM
Rejected
via MITRE·10:09 AM
Data Sourced
via NVD·10:15 AM
Description
Jul 16, 2026
Rejected
via MITRE·03:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-7040?
CVE-2024-7040 is classified as a medium severity vulnerability due to improper access control.
2
How do I fix CVE-2024-7040?
To fix CVE-2024-7040, update to the latest version of open-webui which addresses the access control issue.
3
What is the impact of CVE-2024-7040?
The impact of CVE-2024-7040 allows unauthorized access to chat logs of admin users by modifying the user_id parameter.
4
Who is affected by CVE-2024-7040?
CVE-2024-7040 affects installations of open-webui version v0.3.8.
5
Is there a workaround for CVE-2024-7040?
Currently, there is no specific workaround for CVE-2024-7040, so upgrading is the recommended solution.