Filtered by vendor Linuxfoundation
Subscribe
Filtered by product Loopback-connector-postgresql
Subscribe
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-35942 | 1 Linuxfoundation | 1 Loopback-connector-postgresql | 2024-11-21 | N/A | 9.3 CRITICAL |
|
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the connected database. A patch was released in version 5.5.1. This affects users who does any of the following: - Connect to the database via the DataSource with `allowExtendedProperties: t ...
Show More |
|||||