Описание
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
Ссылки
- MitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.0 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 31%
0.00379
Низкий
6.3 Medium
CVSS3
7.7 High
CVSS3
Дефекты
CWE-285
Связанные уязвимости
CVSS3: 6.3
github
2 месяца назад
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.
EPSS
Процентиль: 31%
0.00379
Низкий
6.3 Medium
CVSS3
7.7 High
CVSS3
Дефекты
CWE-285