Database/Control plane, storage & DevOps
FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filter
Impact
FlyteAdmin's list endpoints interpolate filter parameters into SQL, so a crafted REST request runs attacker-chosen statements against the control-plane database. That database holds every project's and every tenant's workflow, execution and launch-plan records, so the read boundary between projects collapses.
Who can reach it
A user who can reach the FlyteAdmin API. In most deployments that means someone already behind the VPN or holding a valid login.
What to do
Upgrade FlyteAdmin to 1.1.124 or later and restart. Keep FlyteAdmin off the public internet regardless, and review database audit logs for unexpected queries from the admin service account.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.