CVE-2024-24213

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 8, 2024
Updated: Aug 19, 2024
CWE ID 89

Summary

CVE-2024-24213 is a recently disclosed SQL injection vulnerability affecting Supabase PostgreSQL v15.1. Contrary to initial assumptions, this issue is not a typical database exploit but rather an intended feature of the /pg_meta/default/query component. This feature is designed for SQL queries entered through the Supabase dashboard by authorized users, and no unintended injection occurs. The vendor's stance clarifies that no data is susceptible to injection through this path.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share