RuoYi-AI 3.0.0 至 3.1.0 版本存在一个缺失授权漏洞,允许已认证用户通过向 POST /workflow/del/{uuid} 发送请求来删除其他用户的 workflow(工作流)。攻击者可以通过 GET /workflow/search 接口获取 workflow 的 UUID,并将其作为参数传入,因为 softDelete() 方法跳过了 PrivilegeUtil.checkAndGetByUuid() 中的所有权检查,从而导致攻击者能够删除其他用户的工作流。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet