Database/Control plane, storage & DevOps
Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural Compressor
CVE-2024-39368Control plane, storage & DevOpscurated
Impact
SQL injection reachable by an authenticated user of Neural Compressor. Gets an attacker the backing database of the optimisation service - job metadata, model references, and whatever credentials the deployment stored there.
Who can reach it
Any authenticated user of the Neural Compressor service.
What to do
Upgrade to Neural Compressor v3.0 or later. Application-level update, restart the service.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.