Impact
Flow‑Like’s GET /api/v1/apps/{app_id}/invoke/presign endpoint, before version 1.0.4, could issue Azure Blob Storage SAS tokens that grant write and delete permissions on app content to any user who holds ExecuteEvents privileges, even if that user lacks ReadFiles or WriteFiles rights. The endpoint treats file permissions as optional after the ExecuteEvents gate, resulting in a token that allows direct modification or removal of any blob under the app content prefix, thereby compromising data integrity and availability.
Affected Systems
The flaw affects Rheosoph’s Flow‑Like platform on self‑hosted installations that use Azure Blob Storage as their backend and are running a version earlier than 1.0.4. Hosted Flow‑Like Studio and the hosted Flow‑Like Web App, which employ AWS‑backed storage, are not impacted. Self‑hosted deployments that use Azure Blob Storage must update to version 1.0.4 or the latest development branch to eliminate the issue.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating high severity. The attack can be carried out by any authenticated app member who has ExecuteEvents rights but not file‑write permissions, which limits exploitation to legitimate users who possess workflow execution privileges. While the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the ability to write or delete arbitrary blobs can lead to data loss, tampering, or privilege escalation within the affected application, warranting timely remediation.
OpenCVE Enrichment