PT-2024-31775 · Devtron+1 · Devtron+1

Leonnewton

·

Published

2024-11-07

·

Updated

2024-11-22

·

CVE-2024-45794

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Devtron versions prior to 0.7.2
Description: Devtron is an open source tool integration platform for Kubernetes. An authenticated user with minimum permission could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via the CreateUser API (/orchestrator/user). The SQL injection can happen in the code where the userInfo parameter can be controlled by users, allowing the creation and execution of malicious SQL queries. The user should be authenticated but only needs minimum permissions.
Recommendations: For Devtron versions prior to 0.7.2, update to version 0.7.2 to address this issue promptly. As a temporary workaround, consider restricting access to the CreateUser API (/orchestrator/user) until the update is applied. Avoid using the userInfo parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-45794
GHSA-Q78V-CV36-8FXJ
GO-2024-3260
OPENSUSE-SU-2024:14482-1
OPENSUSE-SU-2024_4042-1
SUSE-SU-2024:4042-1

Affected Products

Devtron
Suse