blob: b4cfc79611eefe5f489a98c5c8d9210941d05146 [file] [log] [blame]
id: GO-2024-3260
modules:
- module: github.com/devtron-labs/devtron
versions:
- fixed: 0.7.2
vulnerable_at: 0.7.2-rc.0
summary: Devtron has SQL Injection in CreateUser API in github.com/devtron-labs/devtron
cves:
- CVE-2024-45794
ghsas:
- GHSA-q78v-cv36-8fxj
references:
- advisory: https://github.com/devtron-labs/devtron/security/advisories/GHSA-q78v-cv36-8fxj
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-45794
- fix: https://github.com/devtron-labs/devtron/commit/1540271bd777b6bccd288e513a9070d8f04b6056
source:
id: GHSA-q78v-cv36-8fxj
created: 2024-11-08T12:15:13.627476-05:00
review_status: UNREVIEWED