Flyte Admin SQL Injection in List Filters
Description
Published to the GitHub Advisory Database
Oct 27, 2023
Reviewed
Oct 27, 2023
Published by the National Vulnerability Database
Oct 30, 2023
Last updated
Nov 9, 2023
Impact
List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.
Workarounds
The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).
References
https://owasp.org/www-community/attacks/SQL_Injection#
References