Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id
Vulnerability Description
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
IBM Langflow 安全漏洞
Vulnerability Description
IBM Langflow是美国国际商业机器(IBM)公司的一个可视化流程编排工具。 IBM Langflow 1.0.0至1.8.4版本存在安全漏洞,该漏洞源于任何用户可提供flow_id读取其他用户的事务日志和顶点构建数据,并删除其他用户流程的持久化顶点构建数据。
CVSS Information
N/A
Vulnerability Type
N/A