漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
Vulnerability Description
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
FlowiseAI Flowise 输入验证错误漏洞
Vulnerability Description
FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise 2.2.4及之前版本存在输入验证错误漏洞,该漏洞源于在storageType设置为local时,未经身份验证的攻击者可利用chatId和chatflowId参数中的路径遍历,通过/api/v1/attachments端点上传恶意文件至任意目录,可能导致远程代码执行和服务器被攻破。
CVSS Information
N/A
Vulnerability Type
N/A