Impact
A blind SQL injection flaw exists in the legacy dashboard widget API of Google SecOps Chronicle SOAR, allowing an authenticated user to craft request parameters that are directly incorporated into SQL queries. The vulnerability can lead to unauthorized database access, data extraction or manipulation, and potentially broader system compromise. This weakness is identified as CWE‑89.
Affected Systems
The flaw affects Google Cloud Google SecOps (Chronicle SOAR) deployments running any version prior to 6.3.85. Customers using older releases of the dashboard widget API are susceptible until they upgrade to the patched version.
Risk and Exploitability
With a CVSS score of 9.4, the risk is high. The EPSS is currently not available, and the issue is not listed in CISA’s KEV catalog, indicating no widespread exploitation evidence at this time. An attacker must be authenticated to the service and must interact with the legacy dashboard widget endpoint to send malicious parameters, after which blind SQL queries can be executed against the underlying database.
OpenCVE Enrichment