One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8319961
Date de publication 2023-03-20 13:15:11 (vue: 2023-03-20 15:06:52)
Titre CVE-2023-28424
Texte Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated attackers can execute arbitrary SQL queries on `https://packages.gentoo.org/`. It was also demonstrated that primitive was enough to gain code execution in the context of the PostgreSQL container. The issue was addressed in commit `4fa6e4b619c0362728955b6ec56eab0e0cbf1e23y` of version 1.0.2 using prepared statements to interpolate user-controlled data in SQL queries.
Envoyé Oui
Condensat 2023 28424 `4fa6e4b619c0362728955b6ec56eab0e0cbf1e23y` `https://packages `pkg/app/handler/packages/search `q` `search` `searchfeed` addressed affected also arbitrary are attackers can code commit container context controlled cve data demonstrated enough execute execution gain gentoo go` handlers implemented injection interpolate issue org org/` package packages parameter postgresql powers prepared primitive prior queries result search soko sql statements two unauthenticated user using version
Tags
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: