脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
脆弱性説明
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator's configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users' data. This issue is fixed in 0.11.0.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
脆弱性タイプ
授权机制缺失
脆弱性タイトル
Open WebUI 授权问题漏洞
脆弱性説明
Open WebUI是Open WebUI团队开源的一个可扩展、功能丰富、用户友好的自托管 WebUI。 Open WebUI 0.7.0版本至0.11.0之前版本存在授权问题漏洞,该漏洞源于遗留的chat-completions功能信任客户端提供的image_generation标志,且未重新检查features.image_generation权限,可能导致已认证用户的图像生成权限被撤销后仍可通过chat completions消耗操作员配置的图像提供商资源,花费API积分和提供商配额,并将生成的文件
CVSS情報
N/A
脆弱性タイプ
N/A