CVE-2024-7049

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 10, 2024
Updated: Oct 17, 2024
CWE ID 488

Summary

CVE-2024-7049 is a newly disclosed vulnerability affecting open-webui version v0.3.8. This issue grants unauthorized access to users with pending roles, as they receive a token upon login. Consequently, these users can bypass the admin confirmation process and execute actions without approval. This weakness in the approval process could potentially result in significant security implications for affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share