Open WebUI

CPE Details

Open WebUI
-
2024-10-17
10h22 +00:00
2024-10-17
10h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openwebui:open_webui:-:*:*:*:*:*:*:*

Informations

Vendor

openwebui

Product

open_webui

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-7806 2025-03-20 10h11 +00:00 A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the SameSite attribute set to lax for authentication and lacks CSRF tokens. This allows an attacker to craft a malicious HTML that, when accessed by a victim, can modify the Python code of an existing pipeline and execute arbitrary code with the victim's privileges.
8.8
High
CVE-2024-7038 2024-10-09 18h26 +00:00 An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
2.7
Low