The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade flowise to version 3.1.3 or higher.
flowise is a Flowiseai Server
Affected versions of this package are vulnerable to Incorrect Authorization in the OAuth2 credential handling process due to insufficient workspace scoping and authentication checks on the authorize, callback, and refresh endpoints. An attacker can access or manipulate OAuth2 credentials belonging to other workspaces by sending crafted requests to these endpoints. This allows unauthorized retrieval of credential metadata, injection of attacker-controlled tokens, and refreshing of tokens for any credential, potentially leading to unauthorized access to connected external services.