Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40061
HistoryApr 06, 2023 - 12:07 p.m.

SQL Injection

2023-04-0612:07:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
sql injection
hashicorp/vault
mssql.go
validation
parameters
schema
database
table
attacker
arbitrary sql queries

0.0004 Low

EPSS

Percentile

9.0%

github.com/hashicorp/vault is vulnerable to SQL Injection. The vulnerability exists in mssql.go due to improper validation of parameters such as schema, database, and table which allows an attacker to inject and execute arbitrary sql queries.

0.0004 Low

EPSS

Percentile

9.0%