Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.7epss 0.4%
probabilidad de explotación
0.4%top 62% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
FlowiseAI · FlowisePoCs públicas encontradas — 1
cve_referencegist.github.com/haidang-infosec/402db84bee7aca2f57bb109b31574649?utm_source=chatgpt.comno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.