漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Flowise: Sensitive Data Leak in public-chatbotConfig
Vulnerability Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers, leading to credential theft and more. This vulnerability is fixed in 3.1.0.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Flowise 信息泄露漏洞
Vulnerability Description
Flowise是FlowiseAI开源的一个用于轻松构建 LLM 应用程序的工具。 Flowise 3.1.0之前版本存在信息泄露漏洞,该漏洞源于/api/v1/public-chatbotConfig/:id端点暴露敏感数据,包括API密钥和HTTP授权标头,导致凭据泄露。
CVSS Information
N/A
Vulnerability Type
N/A