Intel

AIKIDO-2024-10031

n8n is vulnerable to Improper Restriction of Excessive Authentication Attempts

Improper Restriction of Excessive Authentication Attempts Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 18, 2024

10

Low Risk

This Affects:

JSn8n
0.2.0 - 1.35.0
Fixed in 1.36.0
Are you affected? Scan for Free

TL;DR

Vulnerable versions lack adequate protections to prevent multiple failed authentication attempts within a short time frame, making them more vulnerable to brute force attacks. The updated version introduces an optional rate-limiting login endpoint to help mitigate brute force password guessing attacks.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and if your workflow tool is accessible from outside your network or if you are not using 2FA.

Background info

n8n is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.2.0 - 1.35.0.

How to fix this

Upgrade the n8n library to the patch version.