diff --git a/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json b/advisories/github-reviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json similarity index 65% rename from advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json rename to advisories/github-reviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json index 4b4ac5adb91..e5c684cc92b 100644 --- a/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json +++ b/advisories/github-reviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3p9q-7w63-3f8q", - "modified": "2025-03-20T12:32:45Z", + "modified": "2025-03-21T17:30:18Z", "published": "2025-03-20T12:32:45Z", "aliases": [ "CVE-2024-7033" ], + "summary": "Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint", "details": "In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write files to arbitrary locations on the server's filesystem. This can result in overwriting critical system or application files, causing denial of service, or potentially achieving remote code execution (RCE). RCE can allow an attacker to execute malicious code with the privileges of the user running the application, leading to a full system compromise.", "severity": [ { @@ -13,12 +14,36 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.8" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7033" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, { "type": "WEB", "url": "https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1" @@ -29,8 +54,8 @@ "CWE-29" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T17:30:18Z", "nvd_published_at": "2025-03-20T10:15:34Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json b/advisories/github-reviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json similarity index 50% rename from advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json rename to advisories/github-reviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json index 04ef6019f2a..a6c329fc36e 100644 --- a/advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json +++ b/advisories/github-reviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-chf7-q7m5-fq92", - "modified": "2025-03-20T12:32:43Z", + "modified": "2025-03-21T17:29:27Z", "published": "2025-03-20T12:32:43Z", "aliases": [ "CVE-2024-12537" ], + "summary": "Open WebUI Uncontrolled Resource Consumption vulnerability", "details": "In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.", "severity": [ { @@ -13,12 +14,59 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.32" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.32" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12537" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, + { + "type": "WEB", + "url": "https://github.com/open-webui/open-webui/blob/e8babe62bc8e466be0367703fd062a981f5c2394/src/lib/apis/utils/index.ts#L25-L56" + }, { "type": "WEB", "url": "https://huntr.com/bounties/edabd06c-acc0-428c-a481-271f333755bc" @@ -29,8 +77,8 @@ "CWE-400" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T17:29:26Z", "nvd_published_at": "2025-03-20T10:15:29Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json b/advisories/github-reviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json similarity index 67% rename from advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json rename to advisories/github-reviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json index 58ca1d34cc2..15b9d6f4e57 100644 --- a/advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json +++ b/advisories/github-reviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-crh6-pj8c-xrhc", - "modified": "2025-03-20T12:32:45Z", + "modified": "2025-03-21T17:30:06Z", "published": "2025-03-20T12:32:45Z", "aliases": [ "CVE-2024-7034" ], + "summary": "Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint", "details": "In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames. The vulnerability arises from the usage of `file_path = f\"{UPLOAD_DIR}/{file.filename}\"` without proper input validation or sanitization. An attacker can exploit this by manipulating the `file.filename` parameter to include directory traversal sequences, causing the resulting `file_path` to escape the intended `UPLOAD_DIR` and potentially overwrite arbitrary files on the system. This can lead to unauthorized modifications of system binaries, configuration files, or sensitive data, potentially enabling remote command execution.", "severity": [ { @@ -13,12 +14,36 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.8" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7034" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, { "type": "WEB", "url": "https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613" @@ -29,8 +54,8 @@ "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T17:30:06Z", "nvd_published_at": "2025-03-20T10:15:35Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json b/advisories/github-reviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json similarity index 51% rename from advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json rename to advisories/github-reviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json index ae1f61cd619..793460d7fcb 100644 --- a/advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json +++ b/advisories/github-reviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g3mx-83mp-3rwc", - "modified": "2025-03-20T12:32:43Z", + "modified": "2025-03-21T17:30:09Z", "published": "2025-03-20T12:32:43Z", "aliases": [ "CVE-2024-12534" ], + "summary": "Open WebUI Uncontrolled Resource Consumption vulnerability", "details": "In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs. This vulnerability can lead to a Denial of Service (DoS) condition when a user submits excessively large strings, exhausting server resources such as CPU, memory, and disk space, and rendering the service unavailable for legitimate users. This makes the server susceptible to resource exhaustion attacks without requiring authentication.", "severity": [ { @@ -13,12 +14,59 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.32" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.32" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12534" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, + { + "type": "WEB", + "url": "https://github.com/open-webui/open-webui/blob/e8babe62bc8e466be0367703fd062a981f5c2394/src/lib/apis/auths/index.ts#L113-L142" + }, { "type": "WEB", "url": "https://huntr.com/bounties/c7c0a4e6-acd3-49b4-8684-2c2c27014b76" @@ -29,8 +77,8 @@ "CWE-400" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T17:30:09Z", "nvd_published_at": "2025-03-20T10:15:29Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json b/advisories/github-reviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json similarity index 61% rename from advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json rename to advisories/github-reviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json index 0665874ef10..20709b888ba 100644 --- a/advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json +++ b/advisories/github-reviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pqwr-phvv-v49f", - "modified": "2025-03-20T12:32:45Z", + "modified": "2025-03-21T17:29:56Z", "published": "2025-03-20T12:32:45Z", "aliases": [ "CVE-2024-7039" ], + "summary": "Open WebUI Allows Admin Deletion via API Endpoint", "details": "In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an admin, to delete other administrators via the API endpoint `http://0.0.0.0:8080/api/v1/users/{uuid_administrator}`. This action is restricted by the user interface but can be performed through direct API calls.", "severity": [ { @@ -13,12 +14,36 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.8" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7039" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, { "type": "WEB", "url": "https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc" @@ -29,8 +54,8 @@ "CWE-269" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T17:29:56Z", "nvd_published_at": "2025-03-20T10:15:35Z" } } \ No newline at end of file