Flowise是一个用于轻松构建 LLM 应用程序的工具。 Flowise 1.4.3 版本存在安全漏洞,该漏洞源于跨域资源共享配置错误得将 Access-Control-Allow-Origin 标头设置为全部,允许任意来源连接到网站。在默认配置(未经身份验证)下,任意来源可能能够向 Flowise 发出请求,窃取用户信息。此 CORS 配置错误可能与路径注入相结合,允许攻击者(无需访问 Flowise)从 Flowise 服务器读取任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-36420 | 7.5 HIGH | GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file |
| CVE-2024-37146 | 6.1 MEDIUM | GHSL-2023-248: Flowise xss in /api/v1/credentials/id |
| CVE-2024-37145 | 6.1 MEDIUM | GHSL-2023-247: Flowise xss in /api/v1/chatflows-streaming/id |
| CVE-2024-36423 | 6.1 MEDIUM | GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id |
| CVE-2024-36422 | 6.1 MEDIUM | GHSL-2023-245: Flowise xss in api/v1/chatflows/id |
No comments yet