Skip to main content

CVE-2024-7049

Severity Medium
Score 5.4/10

Summary

In open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

Advisory Timeline

  • Published