mirror of
https://github.com/open-webui/docs.git
synced 2026-07-21 01:55:22 -04:00
Label rejected dispositions as CNA REJECTED
This commit is contained in:
@@ -44,13 +44,13 @@ For a full overview, see the [Security Policy](../security-policy).
|
||||
|
||||
| CVE | Title | Vendor Disposition | Official Resolution | Published |
|
||||
| :--- | :--- | :--- | :--- | :--- |
|
||||
| [CVE-2025-15603](./cve-2025-15603) | Insufficiently Random Values in start_windows.bat | Rejected | <span className="badge badge--success">REJECTED</span> | 2026-03-09 |
|
||||
| [CVE-2025-15603](./cve-2025-15603) | Insufficiently Random Values in start_windows.bat | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2026-03-09 |
|
||||
| [CVE-2026-0765](./cve-2026-0765) | PIP install_frontmatter_requirements Command Injection | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">REJECTED</span> | 2025-12-18 |
|
||||
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-12-18 |
|
||||
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 |
|
||||
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">REJECTED</span> | 2025-04-21 |
|
||||
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-04-21 |
|
||||
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 |
|
||||
|
||||
Reference in New Issue
Block a user