PT-2024-31775 · Devtron+1 · Devtron+1
Leonnewton
·
Published
2024-11-07
·
Updated
2024-11-22
·
CVE-2024-45794
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Devtron versions prior to 0.7.2
Description:
Devtron is an open source tool integration platform for Kubernetes. An authenticated user with minimum permission could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via the CreateUser API (/orchestrator/user). The SQL injection can happen in the code where the
userInfo parameter can be controlled by users, allowing the creation and execution of malicious SQL queries. The user should be authenticated but only needs minimum permissions.Recommendations:
For Devtron versions prior to 0.7.2, update to version 0.7.2 to address this issue promptly. As a temporary workaround, consider restricting access to the CreateUser API (/orchestrator/user) until the update is applied. Avoid using the
userInfo parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devtron
Suse