RuoYi-AI 3.0.0 至 3.1.0 版本在 GET /workflow/search 接口中存在缺失授权检查的安全漏洞,可导致其他用户的私有工作流被泄露。经过身份认证的非管理员用户能够访问该接口(该接口未进行所有者或公开状态过滤),从而列出同一租户下已启用的私有工作流,包括工作流的 UUID 以及完整的节点和边配置信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet