LangGenius Dify
cpe:2.3:a:langgenius:dify:*:*:*:*:node.js:*:*
- 1.9.1
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify version 1.9.1, specifically within the '/console/api/setup' endpoint. This vulnerability arises from an insecure CORS policy that indiscriminately reflects any Origin header and allows 'Access-Control-Allow-Credentials: true'. As a result, arbitrary external domains can make authenticated requests to the endpoint.
Exploitation of this vulnerability could lead to unauthorized access to sensitive installation and setup information by allowing external domains to make authenticated requests to the vulnerable endpoint.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.