Record summary

EIP currently links 1 Nuclei template to CVE-2024-8181.

Description

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 29, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

VulnCheck, CVE List1.8.2affected
GitHub AdvisoryThrough 1.8.2affected

Nuclei templates

1
ProjectDiscoveryHIGHFlowise <= 1.8.2 Authentication BypassCVSS 7.3

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

Impact

Unauthenticated attackers can bypass authentication to access administrative API endpoints, gaining unauthorized access to restricted functionality, API keys, and administrative operations.

Remediation

Update Flowise to a version later than 1.8.2 to address the authentication bypass vulnerability.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagstenablecvecve2024flowiseauth-bypassvkevvulnai
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Shodan: http.favicon.hash:-2051052918
FOFA: title:"Flowise"

Source: ProjectDiscovery

References

4