Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-397m-c2vg-wm77

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 7.1

Описание

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.

EPSS

Процентиль: 26%
0.00328
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.1
nvd
3 дня назад

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.

EPSS

Процентиль: 26%
0.00328
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862