漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
Vulnerability Description
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position.
To remediate this issue, users should upgrade to version 1.0.13 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Amazon MCP Gateway & Registry SQL注入漏洞
Vulnerability Description
Amazon MCP Gateway & Registry是美国Amazon公司的一款网关与注册表服务。 Amazon MCP Gateway & Registry存在SQL注入漏洞,该漏洞源于metrics-service retention policy management组件中对特殊元素的中和不正确,可能导致经过身份验证的远程用户通过特制的table_name值在标识符位置嵌入SQL语句,执行任意SQL查询。以下版本受到影响:1.0.13之前版本。
CVSS Information
N/A
Vulnerability Type
N/A