GHSL-2024-033: Server-Side Request Forgery (SSRF) in open-webui - CVE-2024-30256
Published Apr 18, 2024
·Updated
Open-webui is vulnerable to authenticated blind server-side request forgery.
Affected Software
1 affected component
open-webui
Event History
Apr 18, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2024-033?
GHSL-2024-033 has a risk rating of 44, indicating a moderate level of severity.
2
How do I fix GHSL-2024-033?
To mitigate GHSL-2024-033, update to the latest version of open-webui or implement appropriate network controls to limit server-side requests.
3
What is a server-side request forgery in the context of GHSL-2024-033?
In GHSL-2024-033, server-side request forgery allows an authenticated user to make unintended requests from the server, potentially accessing sensitive data.
4
Which versions of open-webui are affected by GHSL-2024-033?
GHSL-2024-033 affects earlier versions of open-webui prior to the security updates released on April 18, 2024.
5
Who is responsible for discovering GHSL-2024-033?
The vulnerability GHSL-2024-033 was reported by the security team at open-webui.