Vulnerabilities > CVE-2024-7049 - Unspecified vulnerability in Openwebui Open Webui 0.3.8
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |