In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.
History

Thu, 27 Mar 2025 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 26 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Openwebui
Openwebui open Webui
Weaknesses CWE-306
CPEs cpe:2.3:a:openwebui:open_webui:0.3.10:*:*:*:*:*:*:*
Vendors & Products Openwebui
Openwebui open Webui
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Thu, 20 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.
Title Improper Authentication in open-webui/open-webui
Weaknesses CWE-287
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-27T10:44:22.552Z

Reserved: 2024-08-21T17:43:42.543Z

Link: CVE-2024-8053

cve-icon Vulnrichment

Updated: 2025-03-20T13:10:17.993Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:39.993

Modified: 2025-03-27T11:15:36.737

Link: CVE-2024-8053

cve-icon Redhat

No data.