漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Path Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload Endpoint
Vulnerability Description
IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
IBM Langflow Desktop 路径遍历漏洞
Vulnerability Description
IBM Langflow Desktop是美国国际商业机器(IBM)公司的一款AI流程编排桌面应用。 IBM Langflow Desktop 1.8.4及之前版本存在路径遍历漏洞,该漏洞源于目录遍历,可能导致远程攻击者通过特制URL请求查看任意文件。
CVSS Information
N/A
Vulnerability Type
N/A