CORS Misconfiguration in Flowise Allows Arbitrary Origins to Access Sensitive Information
CVE-2024-36421
What is CVE-2024-36421?
In Flowise version 1.4.3, a CORS misconfiguration allows the Access-Control-Allow-Origin header to accept requests from any origin. This vulnerability poses a significant risk as unauthenticated users can potentially make requests to the application, enabling them to steal sensitive information from users. Furthermore, this misconfiguration can be exploited alongside path injection techniques, allowing attackers without direct access to Flowise to read arbitrary files stored on the server. Current knowledge indicates that no patches are available to address this issue at the time of reporting.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flowise <= 1.4.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
