Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63gf-x2fr-8r32

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the PUT and COPY commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as /etc/passwd, by exploiting the exposed SQL queries through a Python Flask API.

Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the PUT and COPY commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as /etc/passwd, by exploiting the exposed SQL queries through a Python Flask API.

EPSS

Процентиль: 23%
0.00074
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python Flask API.

EPSS

Процентиль: 23%
0.00074
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-89