GHSA-v5wf-jg37-r9m5
SQLpage vulnerable to public exposure of database credentials
Details
### Impact
If - you are using a SQLPage version older than v0.11.1 - your SQLPage instance is exposed publicly - the database connection string is specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable) - the web_root is the current working directory (the default) - your database is exposed publicly
then an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly.
### Patches
Upgrade to [v0.11.1](https://github.com/lovasoa/SQLpage/releases/tag/v0.11.1) as soon as possible.
### Workarounds
If you cannot upgrade immediately:
- Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. - Using a different [web root](https://github.com/lovasoa/SQLpage/blob/main/configuration.md) (that is not a parent of the SQLPage configuration directory) fixes the issue. - And in any case, you should generally avoid exposing your database publicly
### References
https://github.com/lovasoa/SQLpage/issues/89
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.11.1Upgrade sqlpage to 0.11.1 or newer (ecosystem crates.io).