CVE Vulnerabilities

CVE-2024-7297

Improper Control of Dynamically-Managed Code Resources

Published: Jul 30, 2024 | Modified: Jul 30, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the /api/v1/users endpoint.

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Potential Mitigations

References