Опубликовано: 27 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
Flowise Unauthenticated Denial of Service (DoS) vulnerability
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the /api/v1/get-upload-file api endpoint.
Пакеты
Наименование
flowise
npm
Затронутые версииВерсия исправления
<= 1.8.2
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
больше 1 года назад
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.