CVE-2024-8053 is an unauthenticated access vulnerability in the api/v1/utils/pdf endpoint of open-webui/open-webui version v0.3.10, allowing attackers to access the PDF generation service without authentication. This vulnerability carries a high severity CVSS score of 8.2, enabling unauthenticated attackers to trigger denial of service (DoS) through resource exhaustion via large payloads, and to misuse the service for unauthorized PDF generation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.3.10CPE matchmatch criteria | cpe:2.3:a:openwebui:open_webui:0.3.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.