You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
leonnewton
changed the title
[wall-of-fame]: Finding SQL Injection in sqlKvStore of LF Edge eKuiper with CodeQL
[wall-of-fame]: Finding SQL Injection with CodeQL
Nov 8, 2024
Hi @xcorail
Yes, there is no additional write up. But there are details about the vulnerabilities in the advisories, e.g., the root cause, Poc code, the source and sink of data flow detected by CodeQL.
Yeah, I can see all those details in the advisories, however, there is no explicit mention that these issues were found with the help of CodeQL (unless I missed it), even if I know that CodeQL could find those.
I wouldn't want to give credit to CodeQL without this explicit mention coming from the reporters (you). As all details are already in the advisories, a very short write-up stating that would suffice, or the addition directly in the advsories.
Uh oh!
There was an error while loading. Please reload this page.
Date
2024-08-27
Title
Finding SQL Injeciton in LF Edge eKuiper and Devtron
Author
Yuan Luo
URL
GHSA-r5ph-4jxm-6j9p
GHSA-q78v-cv36-8fxj
CVE
CVE-2024-43406, CVE-2024-45794
Description
Using CodeQL to scan repos to find SQL injections.
The text was updated successfully, but these errors were encountered: