Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
Vulnerability Description
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
n8n 竞争条件问题漏洞
Vulnerability Description
n8n是n8n公司开源的一款支持持续集成与交付的工作流自动化工具。 n8n 1.123.64之前版本、2.29.8之前版本和2.30.1之前版本存在竞争条件问题漏洞,该漏洞源于Git节点克隆操作存在竞争条件问题,允许认证工作流用户在克隆前将已验证目录替换为符号链接,植入特制仓库,重启后作为自定义JavaScript节点加载并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A