In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Open-webui
Open-webui open-webui |
|
CPEs | cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Open-webui
Open-webui open-webui |
|
Metrics |
ssvc
|
Thu, 10 Oct 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models. | |
Title | IDOR in open-webui/open-webui | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-10T01:22:16.902Z
Updated: 2024-10-10T14:48:56.131Z
Reserved: 2024-07-23T19:08:19.449Z
Link: CVE-2024-7048
Vulnrichment
Updated: 2024-10-10T14:48:50.628Z
NVD
Status : Awaiting Analysis
Published: 2024-10-10T02:15:03.113
Modified: 2024-10-10T12:51:56.987
Link: CVE-2024-7048
Redhat
No data.