Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r847-6w6h-r8g4

Опубликовано: 27 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

Flyte Admin SQL Injection in List Filters

Impact

List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.

Workarounds

The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).

References

https://owasp.org/www-community/attacks/SQL_Injection#

Пакеты

Наименование

github.com/flyteorg/flyteadmin

go
Затронутые версииВерсия исправления

< 1.1.124

1.1.124

EPSS

Процентиль: 55%
0.00327
Низкий

3.5 Low

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 3.5
nvd
больше 2 лет назад

FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue.

EPSS

Процентиль: 55%
0.00327
Низкий

3.5 Low

CVSS3

Дефекты

CWE-89