漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Langflow: Unauthenticated DoS through multipart form boundary file upload
Vulnerability Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Langflow 资源管理错误漏洞
Vulnerability Description
Langflow是Langflow团队开源的一个用于构建多代理和 RAG 应用程序的可视化框架。 Langflow 1.0.19之前版本存在资源管理错误漏洞,该漏洞源于资源管理错误,可能导致攻击者通过发送/api/v1/files/upload/请求,无需认证利用超长多部分表单边界,使应用长时间不可用。
CVSS Information
N/A
Vulnerability Type
N/A