Skip to content
RudderStackGHSA-3jmm-f6jj-rcc3

rudder-server is vulnerable to SQL injection

Critical8.8CVE-2023-30625 · Published Aug 5, 2024 · updated Nov 18, 2024

rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/rudderlabs/rudder-server
Go
< 1.3.0-rc.11.3.0-rc.1
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.