First published: Tue Jul 30 2024(Updated: )
Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Langflow | <1.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7297 is a high-severity privilege escalation vulnerability in Langflow versions prior to 1.0.13.
To fix CVE-2024-7297, upgrade Langflow to version 1.0.13 or later.
CVE-2024-7297 affects all users of Langflow versions prior to 1.0.13.
CVE-2024-7297 is classified as a privilege escalation vulnerability.
An attacker exploiting CVE-2024-7297 can perform a mass assignment request to gain super admin privileges.