Arbitrary File Write Vulnerability in eosphoros-ai/db-gpt Product by Eosphoros
CVE-2024-10835
9.8CRITICAL
What is CVE-2024-10835?
The eosphoros-ai/db-gpt version v0.6.0 contains a security flaw in its web API that allows unauthorized execution of arbitrary SQL queries. Specifically, the endpoint POST /api/v1/editor/sql/run lacks proper access control measures, enabling malicious actors to exploit this weakness. By leveraging DuckDB SQL, attackers can perform arbitrary file write operations that may compromise the victim's file system, leading to potential remote code execution scenarios. It is crucial for users of this product to implement immediate mitigations to safeguard against exploitation.
Affected Version(s)
eosphoros-ai/db-gpt <= unspecified
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
