Database/Control plane, storage & DevOps
Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural Compressor
CVSS 8.0CVE-2024-39368Control plane, storage & DevOpscurated
Impact
SQL injection reachable by an authenticated user of Neural Compressor. Gets an attacker the backing database of the optimisation service - job metadata, model references, and whatever credentials the deployment stored there.
Who can reach it
Any authenticated user of the Neural Compressor service.
What to do
Upgrade to Neural Compressor v3.0 or later. Application-level update, restart the service.
References
Related entries
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
- Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller'sCVE-2026-59690 · Progress Kemp LoadMaster Multi TenantHigh
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSCVE-2026-84665 · Jenkins SonarQube Scanner Plugin (dashboard link generation)High
- Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator toCVE-2026-92127 · Jenkins Script Security Plugin (classpath entry approval)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.