PT-2023-28148 · Unknown · Flyteadmin

Sanjana-Sarda

·

Published

2023-10-27

·

Updated

2023-11-07

·

CVE-2023-41891

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FlyteAdmin versions prior to 1.1.124
Description The issue concerns a SQL vulnerability in list endpoints on FlyteAdmin, where a malicious user can send a REST request with custom SQL statements as list filters. This requires the attacker to have access to the FlyteAdmin installation, typically behind a VPN or authentication.
Recommendations For versions prior to 1.1.124, update to version 1.1.124 or later to resolve the issue. As a temporary workaround, consider restricting access to list endpoints on FlyteAdmin to minimize the risk of exploitation. Restrict access to the FlyteAdmin installation, ensuring it is only accessible behind a VPN or with proper authentication.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-41891
GHSA-R847-6W6H-R8G4
GO-2023-2162

Affected Products

Flyteadmin