脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
FlowiseAI Flowise S3 Document Loader S3.ts path traversal
脆弱性説明
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
脆弱性タイプ
对路径名的限制不恰当(路径遍历)
脆弱性タイトル
FlowiseAI Flowise 路径遍历漏洞
脆弱性説明
FlowiseAI Flowise是FlowiseAI公司开源的一个用于轻松构建 LLM 应用程序的工具。 FlowiseAI Flowise存在路径遍历漏洞,该漏洞源于S3 Document Loader组件中的文件packages/components/nodes/documentloaders/S3/S3.ts存在未知函数,可能导致路径遍历攻击。
CVSS情報
N/A
脆弱性タイプ
N/A