CVE-2024-39909

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39909
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39909.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-39909
Aliases
Related
Published
2024-07-12T15:15:11Z
Modified
2025-01-08T16:15:09.130353Z
Summary
[none]
Details

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. A time/boolean SQL Injection is present in the following resource /api/applicationResources via the following parameter packageID. As it can be seen in backend/pkg/database/id_view.go, while building the SQL Query the fmt.Sprintf function is used to build the query string without the input having first been subjected to any validation. This vulnerability is fixed in 2.23.1.

References

Affected packages

Git / github.com/openclarity/kubeclarity

Affected ranges

Type
GIT
Repo
https://github.com/openclarity/kubeclarity
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9

api/v2.*

api/v2.1.0

backend/v2.*

backend/v2.1.0

cis_docker_benchmark_scanner/v2.*

cis_docker_benchmark_scanner/v2.1.0

cli/v2.*

cli/v2.1.0

kubeclarity-v2.*

kubeclarity-v2.0.0-helm
kubeclarity-v2.1.0-helm
kubeclarity-v2.1.1-helm
kubeclarity-v2.1.2-helm
kubeclarity-v2.10.0-helm
kubeclarity-v2.11.0-helm
kubeclarity-v2.12.0-helm
kubeclarity-v2.12.1-helm
kubeclarity-v2.12.2-helm
kubeclarity-v2.13.0-helm
kubeclarity-v2.14.0-helm
kubeclarity-v2.15.1-helm
kubeclarity-v2.16.0-helm
kubeclarity-v2.17.0-helm
kubeclarity-v2.17.1-helm
kubeclarity-v2.18.0-helm
kubeclarity-v2.18.1-helm
kubeclarity-v2.19.0-helm
kubeclarity-v2.2.0-helm
kubeclarity-v2.20.0-helm
kubeclarity-v2.20.1-helm
kubeclarity-v2.21.0-helm
kubeclarity-v2.21.1-helm
kubeclarity-v2.22.0-helm
kubeclarity-v2.22.1-helm
kubeclarity-v2.23.0-helm
kubeclarity-v2.23.1-helm
kubeclarity-v2.3.0-helm
kubeclarity-v2.4.0-helm
kubeclarity-v2.5.0-helm
kubeclarity-v2.6.0-helm
kubeclarity-v2.7.0-helm
kubeclarity-v2.7.1-helm
kubeclarity-v2.8.0-helm
kubeclarity-v2.9.0-helm

runtime_k8s_scanner/v2.*

runtime_k8s_scanner/v2.1.0

runtime_scan/api/v2.*

runtime_scan/api/v2.1.0

runtime_scan/v2.*

runtime_scan/v2.1.0

sbom_db/api/v2.*

sbom_db/api/v2.1.0

sbom_db/backend/v2.*

sbom_db/backend/v2.1.0

shared/v2.*

shared/v2.1.0

v2.*

v2.0.0
v2.1.0
v2.1.1
v2.1.2
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.12.2
v2.13.0
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.17.0
v2.17.1
v2.18.0
v2.18.1
v2.19.0
v2.2.0
v2.20.0
v2.20.1
v2.21.0
v2.21.1
v2.22.0
v2.22.1
v2.23.0
v2.23.1
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.7.1
v2.8.0
v2.9.0