IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another use
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N약점 (CWE)
상세 설명
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file contents with arbitrary data (integrity breach). This breaks the storage ownership boundary between users.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- langflow langflow1.0.0 - 1.10.2other
- apple macosmacos
- linux linux_kernellinux
- microsoft windowswindows
영향받는 구성 (CPE) 4
- langflow langflow≥ 1.0.0 < 1.10.2cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
- apple macoscpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
- linux linux_kernelcpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
- microsoft windowscpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
참고 자료 1
- https://www.ibm.com/support/pages/node/7279990Vendor Advisory
링크 내용 불러오는 중…