SigNoz 0.87.0 至 0.142.0 之前的版本在 v5 query_range API 中未对用户提供遥测字段键名进行转义处理,导致认证用户可以注入 SQL。拥有 Viewer 角色或更高权限的攻击者可以在字段名中嵌入反引号和引号,从而突破标识符和字符串字面量的边界,进而执行任意的 ClickHouse SQL 语句,读取系统表并窃取数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet