CVE-2024-45794 is a high-severity SQL Injection vulnerability affecting Devtron, an open-source tool integration platform for Kubernetes. An authenticated user with minimal permissions can exploit this flaw via the CreateUser API to execute arbitrary SQL queries, leading to potential compromise of confidentiality, integrity, and availability. The vulnerability has a CVSS score of 8.8 (High) due to its network-based attack vector, low attack complexity, and high impact. There are no known active exploits, public exploit code, or significant community discussion surrounding this CVE, and it is not listed in the KEV catalog. Users are advised to upgrade to Devtron version 0.7.2 or later as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.2CPE matchmatch criteria | cpe:2.3:a:devtron:devtron:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.