The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.
{ "binaries": [ { "binary_name": "sql-ledger", "binary_version": "3.0.8-1" } ] }