The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade open-webui to version 0.11.1 or higher.
open-webui is an Open WebUI
Affected versions of this package are vulnerable to Improper Authentication in the get_user_by_oauth_sub or get_user_by_scim_external_id process. An attacker can gain unauthorized access to another user's account, including administrator accounts, by supplying specially crafted OAuth subject claim values containing SQL wildcard characters. This is only exploitable if the deployment uses SQLite as the database backend and the OAuth subject claim is mapped to a user-controlled value, or if a legitimate subject value contains an underscore, which can cause accidental account mismatches. For the SCIM path, the attacker must already possess the SCIM bearer token.