VDB
Sign up
LOW3.5

GHSA-r847-6w6h-r8g4

Flyte Admin SQL Injection in List Filters

Quick fix

GHSA-r847-6w6h-r8g4 — github.com/flyteorg/flyteadmin: upgrade to the fixed version with the command below.

go get github.com/flyteorg/flyteadmin@v1.1.124

Details

### Impact List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.

### Workarounds The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).

### References https://owasp.org/www-community/attacks/SQL_Injection#

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/flyteorg/flyteadmin
Introduced in: 0Fixed in: 1.1.124
Fixgo get github.com/flyteorg/flyteadmin@v1.1.124

References