翻译: Amazon awslabs mysql-mcp-server 的可变 SQL 检测组件中,被禁止的输入列表不完整,可能导致特定上下文的攻击者绕过只读执行门控,并通过 SQL 内联注释(正则表达式引擎未将其视为空白字符)访问文件读取和文件写入的 SQL 汇点。 修复建议: 为修复此问题,用户应升级到版本 1.0.23。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | AWS Labs MySQL MCP Server | ≤ 1.0.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS Labs MySQL MCP Server | 0 ~ 1.0.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet