Junglewise Threat Intelligence

CVE-2023-50718: NocoDB SQL injection in VitessClient

CVE-2023-50718 · Severity: low · CVSS 3.1 · Published 2024-05-13

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source database management platform that allows users to create and manage databases through a web interface. An authenticated user with create access could exploit a SQL injection vulnerability to execute arbitrary database queries, potentially leading to unauthorized access to sensitive data stored in the database.

Technical details

A SQL injection vulnerability exists in the VitessClient.ts file where the table_name parameter is not properly escaped before being used in a raw SQL query. The vulnerable code constructs a query using string interpolation: `select *, table_name as tn from information_schema.columns where table_name = '${args.tn}'`. An authenticated attacker with create access can inject SQL by including a single quote character in the table name to break out of the query context and execute arbitrary SQL commands. The vulnerability requires authentication and database-specific permissions to exploit, but allows an attacker to read or modify database contents. The vulnerability was fixed in version 0.202.10.

Affected products

  • NocoDB NocoDB < 0.202.10

Timeline

  • 2024-05-13: disclosed
  • 2024-05-13: patched: Fixed in version 0.202.10

References

Related threats