CVE-2024-8055
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-8055 is a new SQL injection vulnerability affecting Vanna version 0.6.3. The issue lies in the application's file staging operations using the `PUT` and `COPY` commands with the Snowflake database. An attacker can exploit this vulnerability by injecting malicious SQL queries through a Python Flask API, allowing unauthenticated remote users to read arbitrary local files on the victim server, including sensitive files such as `/etc/passwd`. This can lead to serious data leakage and potential privilege escalation. Users are advised to upgrade to the latest version of Vanna to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vanna