VDB
Sign up
CRITICAL10.0

GHSA-v5wf-jg37-r9m5

SQLpage vulnerable to public exposure of database credentials

Details

### Impact

If - you are using a SQLPage version older than v0.11.1 - your SQLPage instance is exposed publicly - the database connection string is specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable) - the web_root is the current working directory (the default) - your database is exposed publicly

then an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly.

### Patches

Upgrade to [v0.11.1](https://github.com/lovasoa/SQLpage/releases/tag/v0.11.1) as soon as possible.

### Workarounds

If you cannot upgrade immediately:

- Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. - Using a different [web root](https://github.com/lovasoa/SQLpage/blob/main/configuration.md) (that is not a parent of the SQLPage configuration directory) fixes the issue. - And in any case, you should generally avoid exposing your database publicly

### References

https://github.com/lovasoa/SQLpage/issues/89

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/sqlpage
Introduced in: 0Fixed in: 0.11.1

Upgrade sqlpage to 0.11.1 or newer (ecosystem crates.io).

References