Database/Control plane, storage & DevOps
FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filter
Impact
FlyteAdmin's list endpoints interpolate filter parameters into SQL, so a crafted REST request runs attacker-chosen statements against the control-plane database. That database holds every project's and every tenant's workflow, execution and launch-plan records, so the read boundary between projects collapses.
Who can reach it
A user who can reach the FlyteAdmin API. In most deployments that means someone already behind the VPN or holding a valid login.
What to do
Upgrade FlyteAdmin to 1.1.124 or later and restart. Keep FlyteAdmin off the public internet regardless, and review database audit logs for unexpected queries from the admin service account.
References
Related entries
- GitLab EE: reporter-role author of a merge request can reset its approval rulesCVE-2026-7487 · GitLab EE (merge request approval rules, authorization check)Low
- Jenkins: Overall/Manage holders can change Appearance configuration reserved for administratorsCVE-2026-84653 · Jenkins core (Appearance configuration page permission checks)Low
- IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contentsCVE-2018-1993 · IBM Spectrum Scale Local Read Only Cache (LROC)Low
- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsCVE-2019-0174 · DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issueLow
- IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailCVE-2021-29671 · IBM Spectrum Scale file audit loggingLow
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.