First published: Thu Oct 10 2024(Updated: )
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Openwebui Open Webui | =0.3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.