mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
Security vulnerability report - 3rd attempt at contact #574
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @KoreLogicSecurityDisclosures on GitHub (Apr 1, 2024).
A member of our team has discovered a vulnerability in one of your products. It is our desire to pursue a course of responsible disclosure of this vulnerability with your cooperation.
We first attempted contact 2024.03.05 via email to support@openwebui.com.
On 2024.03.12 we submitted the discovery details via the Github Security 'Report a Vulnerability' feature. On 2024.03.12 we invited @tjbck to our private fork of the open-webui project and issued a Pull Request.
Please review our Vulnerability Disclosure Policy at https://korelogic.com/KoreLogic-Public-Vulnerability-Disclosure-Policy.v2.4.txt.
@justinh-rahb commented on GitHub (Apr 1, 2024):
3 week old account, almost no activity. This smells like bot activity.
@tjbck commented on GitHub (Apr 1, 2024):
Feel free to make a PR directly, Thanks!
@KoreLogicSecurityDisclosures commented on GitHub (Apr 1, 2024):
We initially reported two distinct issues via the Github security feature. The PR we have is a suggested mitigation, but it only covers one of the reported issues. In the interest of protecting the OpenWeb-UI user base, we believe it prudent to keep the specifics of the vulnerabilities embargoed until upstream has had an opportunity to implement appropriate mitigations in the source tree. Please contact us using the email address and PGP key provided in the advisories we submitted 2024.03.12 via Github.