Impact
List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.
Patches
Has the problem been patched? What versions should users upgrade to?
Workarounds
The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).
References
https://owasp.org/www-community/attacks/SQL_Injection#
Impact
List endpoints on Flyte Admin has a SQL vulnerability where a malicious user can send a REST requests with custom SQL statements as list filters.
Patches
Has the problem been patched? What versions should users upgrade to?
Workarounds
The attacker needs to have access to the flyteadmin installation (typically either behind a VPN or authentication).
References
https://owasp.org/www-community/attacks/SQL_Injection#