Improper Authentication Affecting flowise package, versions <2.0.6
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.43% (76th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-FLOWISE-7840516
- published 28 Aug 2024
- disclosed 27 Aug 2024
- credit Joshua Martinelle
Introduced: 27 Aug 2024
CVE-2024-8181 Open this link in a new tabHow to fix?
Upgrade flowise
to version 2.0.6 or higher.
Overview
flowise is a Flowiseai Server
Affected versions of this package are vulnerable to Improper Authentication via the API endpoint authentication process. An attacker can gain unauthorized administrative access and manipulate restricted functionalities by bypassing the authentication mechanism.