CVE-2024-8182: Flowise Denial of Service
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.
Other sources
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the /api/v1/get-upload-file api endpoint.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8182?
CVE-2024-8182 is classified as an Unauthenticated Denial of Service (DoS) vulnerability.
What versions of Flowise are affected by CVE-2024-8182?
CVE-2024-8182 affects Flowise version 1.8.2.
How do I fix CVE-2024-8182?
To fix CVE-2024-8182, upgrade to a version of Flowise that is beyond 1.8.2.
What type of vulnerabilities does CVE-2024-8182 represent?
CVE-2024-8182 represents an input handling vulnerability that leads to Denial of Service.
Can CVE-2024-8182 be exploited by unauthenticated users?
Yes, CVE-2024-8182 can be exploited by unauthenticated users, leading to potential service downtime.