-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| open-webui | pip |
The vulnerability stems from improper cookie security attributes in authentication flows. The functions listed all handled session cookie creation/modification and were missing critical 'SameSite=strict' and 'Secure' attributes before the patch (CVE-2024-7806). This allowed cross-origin request forgery as the lax SameSite policy permits some cross-site requests, and missing Secure flag enables transmission over HTTP. The GitHub commit 7e253df explicitly adds these security attributes to these specific authentication functions, confirming they were the vulnerable points.
Ongoing coverage of React2Shell