Описание
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.124 (исключая)
cpe:2.3:a:flyte:flyteadmin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00327
Низкий
3.5 Low
CVSS3
8.8 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
EPSS
Процентиль: 55%
0.00327
Низкий
3.5 Low
CVSS3
8.8 High
CVSS3
Дефекты
CWE-89