iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.6epss 0.3%
probabilidade de exploração
0.3%top 83% das CVEs
exploração observada
nãonenhuma fonte reporta
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
iflytek · astron-agentReferências
https://github.com/iflytek/astron-agenthttps://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/com/iflytek/astron/console/toolkit/service/workflow/WorkflowService.javahttps://github.com/iflytek/astron-agent/issues/1590https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking-via-missing-ownership-check