RULE(RULE ID:338756)

Rule General Information
Release Date: 2025-03-26
Rule Name: Open WebUI Authority Bypass Vulnerability (CVE-2024-7049)
Severity:
CVE ID:
Rule Protection Details
Description: Open WebUI is an open-source, scalable, feature rich, and user-friendly self hosted WebUI. The Open WebUI v0.3.8 version has a security vulnerability. Attackers can exploit this vulnerability to bypass the expected approval process.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Refer to the announcement or patch by the vendor: https://github.com/open-webui/open-webui/releases/tag/v0.3.32