漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints
Vulnerability Description
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute scope. On instances using Advanced Permissions (Enterprise/Cloud) with projects and viewer roles, an authenticated user with the project:viewer role can start new evaluation test runs, cancel in-flight runs, and delete run records for workflows they only have read access to.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
授权机制不正确
Vulnerability Title
n8n 授权问题漏洞
Vulnerability Description
n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 1.123.55之前版本、2.25.7之前版本和2.26.2之前版本存在授权问题漏洞,该漏洞源于在三个改变状态的评估测试运行端点中,使用workflow:read范围而非workflow:execute范围进行授权,导致具有项目查看者角色的用户能够对仅具有读取权限的工作流启动新的评估测试运行、取消正在进行的运行以及删除运行记录。
CVSS Information
N/A
Vulnerability Type
N/A