CVE-2024-7049: Exposure of Token in open-webui/open-webui
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7049?
CVE-2024-7049 is considered a critical vulnerability due to its potential to allow unauthorized actions without admin approval.
How do I fix CVE-2024-7049?
To fix CVE-2024-7049, update to the latest version of open-webui that addresses this vulnerability.
Who is affected by CVE-2024-7049?
Users of open-webui version 0.3.8 are affected by CVE-2024-7049 due to improper role handling.
What are the consequences of CVE-2024-7049?
The consequences of CVE-2024-7049 include potential unauthorized access and actions performed by users with pending roles.
What types of actions can be bypassed due to CVE-2024-7049?
CVE-2024-7049 allows users to perform actions that normally require admin confirmation, circumventing the approval process.