CVE-2024-43406

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
20/08/2024
Last modified:
26/08/2024

Description

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfedge:ekuiper:*:*:*:*:*:*:*:* 1.14.2 (excluding)