Описание
n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads during workflow creation, causing logical integrity violations in target project folder structures.
Ссылки
- MitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.28.0 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 20%
0.0028
Низкий
5 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
github
около 1 месяца назад
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
EPSS
Процентиль: 20%
0.0028
Низкий
5 Medium
CVSS3
Дефекты
CWE-639