216.73.216.6

CVE-2024-45794

· Published 07/11/2024 18:15 · Modified 08/11/2024 19:01

Labels: CVE-2024-45794 2024-11-07CVE-2024-45794CWE-89[email protected]

Essential information

Published
07/11/2024 18:15
Modified
08/11/2024 19:01
Author
Creator
CVSS
8.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CVSS metrics

Description

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References