CVE-2024-8053
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Mar 20, 2025
Updated: Mar 27, 2025
CWE ID 306
Summary
CVE-2024-8053 is a vulnerability affecting open-webui version v0.3.10. The `api/v1/utils/pdf` endpoint is unprotected and permits unauthenticated access to the PDF generation service. Malicious actors can send large payloads in POST requests, potentially causing server resource exhaustion and denial of service (DoS). Furthermore, attackers can generate PDFs without proper verification, leading to operational and financial implications through service misuse.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.