CVE-2024-8181: Flowise Authentication Bypass
Published Aug 27, 2024
·Updated
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
Affected Software
2 affected components
npm/flowise<=1.8.2
FlowiseAI Flowise=1.8.2
Event History
Aug 27, 2024
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverity
Advisory Published
via GitHub·03:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-8181?
CVE-2024-8181 has a medium severity rating due to its potential for unauthorized access to sensitive API endpoints.
2
How do I fix CVE-2024-8181?
To fix CVE-2024-8181, upgrade Flowise to a version later than 1.8.2 where the vulnerability is patched.
3
Who is affected by CVE-2024-8181?
CVE-2024-8181 affects users running Flowise version 1.8.2.
4
What type of vulnerability is CVE-2024-8181?
CVE-2024-8181 is classified as an Authentication Bypass vulnerability.
5
Can CVE-2024-8181 be exploited remotely?
Yes, CVE-2024-8181 can be exploited remotely by an unauthenticated attacker.