BlackTreeCVE IntelligenceCVE-2024-7049Rejected / withdrawn
This CVE record is not an active vulnerability.
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
No vulnerability report or remediation guidance is generated.
BlackTree retains the source record internally for provenance, historical accuracy and link integrity. It is excluded from the active catalogue, searches, totals, priority views and recent-change reporting.