Логотип exploitDog
bind:CVE-2024-12909
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12909

Количество 2

Количество 2

nvd логотип

CVE-2024-12909

11 месяцев назад

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x48g-hm9c-ww42

11 месяцев назад

llama-index-packs-finchat SQL Injection vulnerability

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-12909

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-x48g-hm9c-ww42

llama-index-packs-finchat SQL Injection vulnerability

CVSS3: 10
1%
Низкий
11 месяцев назад

Уязвимостей на страницу