Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41891

Опубликовано: 30 окт. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 8.8
EPSS Низкий

Описание

FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flyte:flyteadmin:*:*:*:*:*:*:*:*
Версия до 1.1.124 (исключая)

EPSS

Процентиль: 55%
0.00327
Низкий

3.5 Low

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 3.5
github
больше 2 лет назад

Flyte Admin SQL Injection in List Filters

EPSS

Процентиль: 55%
0.00327
Низкий

3.5 Low

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89