Логотип exploitDog
bind:CVE-2024-45794
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45794

Количество 3

Количество 3

nvd логотип

CVE-2024-45794

больше 1 года назад

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-q78v-cv36-8fxj

больше 1 года назад

Devtron has SQL Injection in CreateUser API

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4042-1

около 1 года назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45794

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-q78v-cv36-8fxj

Devtron has SQL Injection in CreateUser API

CVSS3: 8.3
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4042-1

Security update for govulncheck-vulndb

около 1 года назад

Уязвимостей на страницу