GHSL-2023-232: _GHSL-2023-234: Path injection, Cross-Site Scripting (XSS) and CORS misconfiguration in Flowise - CVE-2024-36420, CVE-2024-36421, CVE-2024-36422, CVE-2024-36423, CVE-2024-37145, CVE-2024-37146
Flowise is vulnerable to path injection, cross site scripting and CORS misconfiguration vulnerabilities, that may compromise the confidentiality of the information on the host server. In the worst case, it may allow attackers to read files from the Flowise server and read/modify user secrets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2023-232?
The severity of GHSL-2023-232 is rated at 60, indicating a moderate risk.
What vulnerabilities are identified in GHSL-2023-232?
GHSL-2023-232 identifies path injection, Cross-Site Scripting (XSS), and CORS misconfiguration vulnerabilities.
How do I fix GHSL-2023-232?
To fix GHSL-2023-232, it is recommended to update Flowise to the latest version where these vulnerabilities have been addressed.
What could be the impact of GHSL-2023-232?
The impact of GHSL-2023-232 includes potential compromise of information confidentiality and unauthorized access to user secrets.
Which software is affected by GHSL-2023-232?
GHSL-2023-232 affects the Flowise software.