FlowiseGHSA-48x4-mx8f-gr4h
Flowise Unauthenticated Denial of Service (DoS) vulnerability
High7.5CVE-2024-8182 · Published Aug 27, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| flowise npm | <= 1.8.2 | No fix yet |
Details and references
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the `/api/v1/get-upload-file` api endpoint.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2024-8182
More Flowise advisories
All Flowise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 272024 | Flowise Authentication Bypass vulnerability CVE-2024-8181High7.3no fix yet | High7.3 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in api/v1/chatflows/id CVE-2024-36422Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id CVE-2024-37145Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in /api/v1/public-chatflows/id CVE-2024-36423Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cross-site Scripting in/api/v1/credentials/id CVE-2024-37146Medium6.1no fix yet | Medium6.1 | No fix yet |
| Aug 52024 | Flowise Cors Misconfiguration in packages/server/src/index.ts CVE-2024-36421High7.5no fix yet | High7.5 | No fix yet |