Description
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0054 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2. |
Github GHSA |
GHSA-r5ph-4jxm-6j9p | LF Edge eKuiper has a SQL Injection in sqlKvStore |
References
History
Tue, 20 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfedge
Lfedge ekuiper |
|
| CPEs | cpe:2.3:a:lfedge:ekuiper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfedge
Lfedge ekuiper |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2. | |
| Title | LF Edge eKuiper has a SQL Injection in sqlKvStore | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-20T17:42:14.854Z
Reserved: 2024-08-12T18:02:04.966Z
Link: CVE-2024-43406
Updated: 2024-08-20T17:42:10.277Z
Status : Analyzed
Published: 2024-08-20T15:15:24.070
Modified: 2024-08-26T18:30:13.230
Link: CVE-2024-43406
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA