PT-2024-30563 · Lf Edge · Lf Edge Ekuiper

Leonnewton

·

Published

2024-08-20

·

Updated

2024-08-26

·

CVE-2024-43406

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LF Edge eKuiper versions prior to 1.14.2
Description A SQL Injection vulnerability exists in the sqlKvStore of LF Edge eKuiper, allowing the execution of malicious SQL queries via the Get method. This issue affects various handlers, including explainRuleHandler, sourceManageHandler, asyncTaskCancelHandler, and pluginHandler. The rule id can be used to exploit SQL queries, and the delete function is also vulnerable.
Recommendations For versions prior to 1.14.2, update to version 1.14.2 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable sqlKvStore module to minimize the risk of exploitation. Avoid using the rule id in the affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-43406
GHSA-R5PH-4JXM-6J9P
GO-2024-3078
PYSEC-2024-72

Affected Products

Lf Edge Ekuiper