CVE-2023-27564: High severity n8n vulnerability
Published May 10, 2023
·Updated
The n8n package 0.218.0 for Node.js allows Information Disclosure.
Other sources
The n8n package prior to 0.216.1 for Node.js allows Information Disclosure.
Affected Software
2 affected componentsFixes available
npm/n8n<0.216.1
0.216.1
n8n N8n Node.js=0.218.0
Event History
May 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-27564?
CVE-2023-27564 has been classified as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2023-27564?
To fix CVE-2023-27564, you should upgrade the n8n package to version 0.216.1 or later.
3
What type of vulnerability is CVE-2023-27564?
CVE-2023-27564 is an information disclosure vulnerability found in versions of the n8n package prior to 0.216.1.
4
Which versions of n8n are affected by CVE-2023-27564?
Versions of the n8n package prior to 0.216.1, including version 0.218.0, are affected by CVE-2023-27564.
5
Who is potentially impacted by CVE-2023-27564?
Users and developers using affected versions of the n8n package for Node.js are potentially impacted by CVE-2023-27564.