cve/2024/CVE-2024-30256.md

18 lines
690 B
Markdown
Raw Normal View History

2024-06-22 09:37:59 +00:00
### [CVE-2024-30256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-30256)
![](https://img.shields.io/static/v1?label=Product&message=open-webui&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%200.1.117%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-918%3A%20Server-Side%20Request%20Forgery%20(SSRF)&color=brighgreen)
### Description
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/OrenGitHub/dhscanner