Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in nocobase, a low-code development platform, related to how it handles database queries. This issue, if exploited, could allow unauthorized access to sensitive information stored within the application's database. While the primary concern is to confirm if nocobase is in use within our environment, understanding the potential for data exposure is important.
- Database query flaw allows sensitive data access.
- Confirm use of nocobase; assess potential data exposure.
- Understand risk; verify relevance and system exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted SQL statements to the checkSQL function. This function is exposed via the web interface, and since no authentication is required, an unauthenticated attacker can trigger the vulnerability, leading to the disclosure of sensitive database information.
- No authentication needed for access.
- Triggered by injecting SQL into the checkSQL function.
- Risk of accessing sensitive database information.
Live Threat
Current exploitation, exposure, and threat context
A SQL injection vulnerability in the checkSQL function could allow attackers to access sensitive database information by injecting crafted SQL statements. This could occur when the application processes user-supplied input without proper sanitization, potentially exposing the contents of the application's database.
- Database information.
- Via crafted SQL statements.
- Unauthorized access to sensitive data.
Operational Fix
Recommended remediation, mitigation, and detection steps
This SQL injection vulnerability impacts NocoBase deployments. Responsibility likely falls to application owners and platform teams managing the NocoBase instances, with support from network and security teams for exposure assessment. The immediate priority is to inventory all NocoBase instances, determine their internet reachability and business criticality, identify the accountable owner for each instance, and then assess the risk to plan remediation actions.
- Application owners should verify NocoBase instances.
- Confirm external reachability and business criticality.
- Plan remediation based on identified risks.