Lack of data validation In rhc-worker-script
Description
A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel10 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel9 |
1-10 of 25
10
Aliases
1. 2. 3.