Safety vulnerability ID: 72979
The information on this page was manually curated by our Cybersecurity Intelligence Team.
eKuiper affected versions contain a SQL Injection vulnerability in the `Get` and `Delete` methods of `sqlKvStore`. A malicious user can exploit this by injecting arbitrary SQL through the `rule id` parameter, allowing unauthorized execution of SQL queries. This vulnerability is present in several endpoints, including `explainRuleHandler`, `sourceManageHandler`, `asyncTaskCancelHandler`, and `pluginHandler`, potentially leading to data breaches or unauthorized data manipulation.
Latest version: 1.14.7
Python SDK for eKuiper portable plugin
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application