CVE-2024-43406
HIGHLF Edge eKuiper < 1.14.2 - SQL Injection via Get Method in sqlKvStore
Title source: llmDescription
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
References (2)
Core 2
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/lf-edge/ekuiper/security/advisories/GHSA-r5ph-4jxm-6j9p
Scores
CVSS v3
8.8
EPSS
0.0193
EPSS Percentile
83.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (3)
lf-edge/ekuiper
0 - 1.14.2Go
lfedge/ekuiper
< 1.14.2
pypi/ekuiper
0 - 1.14.2PyPI
Published
Aug 20, 2024
Tracked Since
Feb 18, 2026