CVE-2023-41891
Summary
| CVE | CVE-2023-41891 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-30 19:15:00 UTC |
| Updated | 2023-11-07 23:26:00 UTC |
| Description | FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Flyte |
Flyteadmin |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| SQL Injection in List Filters · Advisory · flyteorg/flyteadmin · GitHub |
MISC |
github.com |
|
| Merge pull request from GHSA-r847-6w6h-r8g4 · flyteorg/flyteadmin@b3177ef · GitHub |
MISC |
github.com |
|
| SQL Injection | OWASP Foundation |
MISC |
owasp.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995756 GO (Go) Security Update for github.com/flyteorg/flyteadmin (GHSA-r847-6w6h-r8g4)