LOW3.5
GHSA-r847-6w6h-r8g4
Flyte Admin SQL Injection in List Filters
Quick fix
GHSA-r847-6w6h-r8g4 — github.com/flyteorg/flyteadmin: upgrade to the fixed version with the command below.
go get github.com/flyteorg/flyteadmin@v1.1.124Details
### Impact List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.
### Workarounds The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).
### References https://owasp.org/www-community/attacks/SQL_Injection#
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/flyteorg/flyteadmin
Introduced in:
0Fixed in: 1.1.124Fix
go get github.com/flyteorg/flyteadmin@v1.1.124References
- https://github.com/flyteorg/flyteadmin/security/advisories/GHSA-r847-6w6h-r8g4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-41891[ADVISORY]
- https://github.com/flyteorg/flyteadmin/commit/b3177ef70f068e908140b8a4a9913dfa74f289fd[WEB]
- https://github.com/flyteorg/flyteadmin[PACKAGE]
- https://owasp.org/www-community/attacks/SQL_Injection#[WEB]