CVE-2024-8181
Flowise Authentication Bypass
Record summary
EIP currently links 1 Nuclei template to CVE-2024-8181.
Description
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 29, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | VulnCheck, CVE List | 1.8.2 | affected |
flowiseBrowse npm / flowise | GitHub Advisory | Through 1.8.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHFlowise <= 1.8.2 Authentication BypassCVSS 7.3
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
Impact
Unauthenticated attackers can bypass authentication to access administrative API endpoints, gaining unauthorized access to restricted functionality, API keys, and administrative operations.
Remediation
Update Flowise to a version later than 1.8.2 to address the authentication bypass vulnerability.
Source: ProjectDiscovery