Impact
A SQL injection flaw in the /utils/sql-parser.ts component of Bytebase dbhub version 1.2.0 allows an attacker to send crafted SQL statements that are executed against the database. Because the input is not properly validated or parameterized, the attacker can read or otherwise manipulate data that should be protected, compromising confidentiality and potentially integrity of the database.
Affected Systems
Bytebase dbhub version 1.2.0 is impacted, with the vulnerability located in the /utils/sql-parser.ts component. This component is accessible via a web endpoint, allowing attackers to target the application if the endpoint is exposed to the network.
Risk and Exploitability
The flaw is a classic SQL injection (CWE‑89). No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. SQL injection offers an attacker the ability to read or modify data, jeopardizing confidentiality and integrity. The attack requires remote access to the vulnerable endpoint; no authentication is needed if the endpoint is publicly reachable. Until a vendor patch is released, the risk is considered significant for any systems running the affected version.
OpenCVE Enrichment