Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12NXdmLWpnMzctcjltNc4AA1_y

SQLpage vulnerable to public exposure of database credentials

Impact

If

then an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly.

Patches

Upgrade to v0.11.1 as soon as possible.

Workarounds

If you cannot upgrade immediately:

References

https://github.com/lovasoa/SQLpage/issues/89

Permalink: https://github.com/advisories/GHSA-v5wf-jg37-r9m5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NXdmLWpnMzctcjltNc4AA1_y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: 7 months ago
Updated: 6 months ago


CVSS Score: 10.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Identifiers: GHSA-v5wf-jg37-r9m5, CVE-2023-42454
References: Repository: https://github.com/lovasoa/SQLpage
Blast Radius: 1.0

Affected Packages

cargo:sqlpage
Dependent packages: 0
Dependent repositories: 0
Downloads: 8,713 total
Affected Version Ranges: < 0.11.1
Fixed in: 0.11.1
All affected versions: 0.3.0, 0.3.1, 0.3.2, 0.4.0, 0.4.1, 0.4.4, 0.5.3, 0.6.6, 0.6.7, 0.6.10
All unaffected versions: 0.14.0, 0.15.0, 0.15.1, 0.15.2, 0.16.0, 0.16.1, 0.17.0, 0.17.1, 0.18.0, 0.18.1, 0.18.2, 0.18.3, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.20.3, 0.20.4