Skip to content

SQL injection of notes/search-by-tag

High
syuilo published GHSA-cgwp-vmr4-wx4q Feb 22, 2023

Package

No package listed

Affected versions

< 13.3.3

Patched versions

13.3.3

Description

Impact

タグによるノート検索API(notes/search-by-tag)において、パラメータの検証が不十分なためSQLインジェクションが可能です。

SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag).

Patches

13.3.3で修正されています。

This has been fixed in 13.3.3.

Workarounds

api/notes/search-by-tag へのアクセスを遮断する

Block access to api/notes/search-by-tag

Severity

High

CVE ID

CVE-2023-24812

Weaknesses

No CWEs

Credits