GPU VulnDB

Database/Control plane, storage & DevOps

Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural Compressor

CVE-2024-39368Control plane, storage & DevOpscurated

Impact

SQL injection reachable by an authenticated user of Neural Compressor. Gets an attacker the backing database of the optimisation service - job metadata, model references, and whatever credentials the deployment stored there.

Who can reach it

Any authenticated user of the Neural Compressor service.

What to do

Upgrade to Neural Compressor v3.0 or later. Application-level update, restart the service.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.