Denial of Service Vulnerability in open-webui by open-webui
CVE-2024-7983
7.5HIGH
What is CVE-2024-7983?
In version 0.3.8 of open-webui, a vulnerability exists that allows unauthorized access to an endpoint responsible for converting markdown to HTML. This vulnerability can be exploited by sending a specially crafted markdown payload that forces the server to expend significant resources during the conversion process. As a result, the server may become unresponsive to legitimate requests until the conversion is completed, creating a denial of service condition. This behavior poses a significant risk to service availability and performance.
Affected Version(s)
open-webui/open-webui <= unspecified