脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
脆弱性説明
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.
CVSS情報
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L
脆弱性タイプ
检查时间与使用时间(TOCTOU)的竞争条件
脆弱性タイトル
n8n 竞争条件问题漏洞
脆弱性説明
n8n是n8n公司开源的一款支持持续集成与交付的工作流自动化工具。 n8n 1.123.64之前版本、2.29.8之前版本和2.30.1之前版本存在竞争条件问题漏洞,该漏洞源于Git节点克隆操作存在竞争条件问题,允许认证工作流用户在克隆前将已验证目录替换为符号链接,植入特制仓库,重启后作为自定义JavaScript节点加载并执行任意代码。
CVSS情報
N/A
脆弱性タイプ
N/A