Database/Control plane, storage & DevOps
Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachable
CVE-2024-39766Control plane, storage & DevOpscurated
Impact
A second SQL-injection path in Neural Compressor reachable by an authenticated user. Same consequence as the first: control of the service's backing store.
Who can reach it
Any authenticated user of the service.
What to do
Upgrade to v3.0 or later. Userspace, restart only.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.