Description
The Flowise has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get access to some admin endpoints of the system.
Remediation
Upgrade to the latest version of Flowise
References
Related Vulnerabilities
Jenkins Incorrect Authorization Vulnerability (CVE-2023-27899)
Magento Session Fixation Vulnerability (CVE-2019-7849)
Moodle Improper Input Validation Vulnerability (CVE-2012-0801)
Oracle Database Server CVE-2013-5771 Vulnerability (CVE-2013-5771)
Jboss EAP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-3878)