VDB
Sign up
HIGH8.8

PYSEC-2024-72

Quick fix

PYSEC-2024-72 — ekuiper: upgrade to the fixed version with the command below.

pip install --upgrade 'ekuiper>=1a9c745649438feaac357d282959687012b65503'

Details

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ekuiper
Introduced in: 0Fixed in: 1a9c745649438feaac357d282959687012b65503
Fixpip install --upgrade 'ekuiper>=1a9c745649438feaac357d282959687012b65503'

References