GPU VulnDB

Database/Control plane, storage & DevOps

FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filter

CVE-2023-41891Control plane, storage & DevOpsGHSA-r847-6w6h-r8g4curated

Impact

FlyteAdmin's list endpoints interpolate filter parameters into SQL, so a crafted REST request runs attacker-chosen statements against the control-plane database. That database holds every project's and every tenant's workflow, execution and launch-plan records, so the read boundary between projects collapses.

Who can reach it

A user who can reach the FlyteAdmin API. In most deployments that means someone already behind the VPN or holding a valid login.

What to do

Upgrade FlyteAdmin to 1.1.124 or later and restart. Keep FlyteAdmin off the public internet regardless, and review database audit logs for unexpected queries from the admin service account.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.