devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kubernetes
Kubernetes devtron |
|
CPEs | cpe:2.3:a:kubernetes:devtron:*:*:*:*:*:*:*:* | |
Vendors & Products |
Kubernetes
Kubernetes devtron |
|
Metrics |
ssvc
|
Thu, 07 Nov 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | SQL Injection in CreateUser API in devtron | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-07T17:42:58.662Z
Updated: 2024-11-07T19:33:42.084Z
Reserved: 2024-09-09T14:23:07.501Z
Link: CVE-2024-45794
Vulnrichment
Updated: 2024-11-07T19:33:37.873Z
NVD
Status : Awaiting Analysis
Published: 2024-11-07T18:15:17.150
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-45794
Redhat
No data.