CVE-2024-7049
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Oct 10, 2024
Updated: Oct 17, 2024
CWE ID 488
Summary
CVE-2024-7049 is a newly disclosed vulnerability affecting open-webui version v0.3.8. This issue grants unauthorized access to users with pending roles, as they receive a token upon login. Consequently, these users can bypass the admin confirmation process and execute actions without approval. This weakness in the approval process could potentially result in significant security implications for affected organizations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.