Improper Access Control in Open-WebUI Product by Open-WebUI Vendor
CVE-2024-7043
8.1HIGH
Summary
Open-WebUI version 0.3.8 contains a vulnerability that allows attackers to bypass access control measures. This issue permits unauthorized users to view and delete files stored on the server. Specifically, the application fails to ensure that users are properly authenticated as administrators, leading to exploitation. Attackers are able to directly access endpoints that retrieve information about files uploaded by users and subsequently delete them. As a result, sensitive data may be exposed and manipulated, significantly impacting the confidentiality and integrity of stored information.
Affected Version(s)
open-webui/open-webui <= unspecified
References
CVSS V3.0
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved