rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.
References
Configurations
History
31 Jul 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Jun 2023, 02:07
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:rudderstack:rudder-server:*:*:*:*:*:*:*:* | |
First Time |
Rudderstack
Rudderstack rudder-server |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | (MISC) https://github.com/rudderlabs/rudder-server/commit/0d061ff2d8c16845179d215bf8012afceba12a30 - Patch | |
References | (MISC) https://securitylab.github.com/advisories/GHSL-2022-097_rudder-server/ - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/rudderlabs/rudder-server/commit/9c009d9775abc99e72fc470f4c4c8e8f1775e82a - Patch | |
References | (MISC) https://github.com/rudderlabs/rudder-server/commit/2f956b7eb3d5eb2de3e79d7df2c87405af25071e - Patch | |
References | (MISC) https://github.com/rudderlabs/rudder-server/pull/2652 - Patch | |
References | (MISC) https://github.com/rudderlabs/rudder-server/pull/2663 - Patch | |
References | (MISC) https://github.com/rudderlabs/rudder-server/pull/2664 - Patch |
16 Jun 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-16 17:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-30625
Mitre link : CVE-2023-30625
CVE.ORG link : CVE-2023-30625
JSON object : View
Products Affected
rudderstack
- rudder-server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')