open-webui Insecure Direct Object Reference (IDOR) vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 9, 2024
to the GitHub Advisory Database
•
Updated Oct 9, 2024
Description
Published by the National Vulnerability Database
Oct 9, 2024
Published to the GitHub Advisory Database
Oct 9, 2024
Reviewed
Oct 9, 2024
Last updated
Oct 9, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint
http://0.0.0.0:3000/api/v1/memories/{id}/update
, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.References