Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1793

Опубликовано: 05 июн. 2025
Источник: redhat
CVSS3: 9.1

Описание

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.

A flaw was found in llama-index. SQL injection vulnerabilities exist within multiple vector store integrations in version v0.12.21, allowing an attacker to execute arbitrary SQL queries. This issue enables unauthorized reading and writing of data via crafted SQL commands. Successful exploitation can lead to data breaches and potential compromise of data belonging to other users, which can be triggered remotely without authentication.

Отчет

Ansible LightSpeed does not use Ollama-index and is not installed in this image, therefore this product is not vulnerable by this flaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2aap-cloud-metrics-collector-containerNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2370381llama-index: LlamaIndex SQL Injection Vulnerability

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.

CVSS3: 9.8
github
7 месяцев назад

llama_index vulnerable to SQL Injection

9.1 Critical

CVSS3