漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
eKuiper API endpoints handling SQL queries with user-controlled table names.
Vulnerability Description
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
LF Edge eKuiper SQL注入漏洞
Vulnerability Description
LF Edge eKuiper是LF Edge开源的一个边缘轻量级物联网数据分析软件。 LF Edge eKuiper 2.2.1之前版本存在SQL注入漏洞,该漏洞源于getLast API功能中存在SQL注入漏洞,可能导致执行任意SQL语句。
CVSS Information
N/A
Vulnerability Type
N/A