Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 21 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Supabase
Supabase postgres |
|
| CPEs | cpe:2.3:a:supabase:postgres:15.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Postgresql
Postgresql postgresql |
Supabase
Supabase postgres |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-19T19:55:59.420Z
Reserved: 2024-01-25T00:00:00
Link: CVE-2024-24213
Updated: 2024-08-01T23:19:51.989Z
Status : Modified
Published: 2024-02-08T18:15:08.237
Modified: 2024-11-21T08:59:02.213
Link: CVE-2024-24213
No data.
OpenCVE Enrichment
No data.
Weaknesses