CVE-2024-7049

Publication date

2024-10-10 07:15:55

Family

@huntr_ai

State

PUBLISHED

Description

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.