CVE-2024-31621: Flowise 1.6.5 - Authentication Bypass
Published Apr 21, 2024
·Updated
An issue in FlowiseAI Inc Flowise prior to v1.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Other sources
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
— NVD
Credit
Maerifat Majeed
Affected Software
2 affected componentsFixes available
npm/flowise<1.8.1
1.8.1
FlowiseAI Flowise<=1.6.5
Event History
Apr 21, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Apr 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-31621?
CVE-2024-31621 has been classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-31621?
To fix CVE-2024-31621, upgrade to Flowise version 1.8.1 or later.
3
What software is affected by CVE-2024-31621?
CVE-2024-31621 affects Flowise versions prior to 1.8.1.
4
What is the impact of CVE-2024-31621?
The impact of CVE-2024-31621 allows a remote attacker to execute arbitrary code on the affected systems.
5
Is CVE-2024-31621 a zero-day vulnerability?
CVE-2024-31621 is not classified as a zero-day vulnerability since a patched version is available.