Improper Access Control in Open-WebUI Product by Open-WebUI Vendor
CVE-2024-7043
What is CVE-2024-7043?
Open-WebUI version 0.3.8 contains a vulnerability that allows attackers to bypass access control measures. This issue permits unauthorized users to view and delete files stored on the server. Specifically, the application fails to ensure that users are properly authenticated as administrators, leading to exploitation. Attackers are able to directly access endpoints that retrieve information about files uploaded by users and subsequently delete them. As a result, sensitive data may be exposed and manipulated, significantly impacting the confidentiality and integrity of stored information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
open-webui/open-webui <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
