Описание
A flaw was found in sources-api-go. An authenticated remote user can exploit a SQL injection vulnerability by injecting arbitrary SQL expressions through query parameter filtering. This can lead to unauthorized information disclosure of internal database fields, arbitrary PostgreSQL function execution, and denial of service.
Отчет
This Important SQL injection vulnerability in sources-api-go allows an authenticated console.redhat.com user to execute arbitrary SQL expressions. This could lead to sensitive information disclosure, arbitrary PostgreSQL function execution, and denial of service, making it a significant risk for Red Hat cloud services. The flaw stems from unsanitized user input being directly interpolated into database queries.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
8.8 High
CVSS3
8.8 High
CVSS3