HIGH8.8
PYSEC-2024-72
Quick fix
PYSEC-2024-72 — ekuiper: upgrade to the fixed version with the command below.
pip install --upgrade 'ekuiper>=1a9c745649438feaac357d282959687012b65503'Details
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/ekuiper
Introduced in:
0Fixed in: 1a9c745649438feaac357d282959687012b65503Fix
pip install --upgrade 'ekuiper>=1a9c745649438feaac357d282959687012b65503'