Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.
An attacker sends a crafted GraphQL query to the run_sql endpoint, injecting malicious system commands (command injection). The attack mechanism exploits PostgreSQL functionality called COPY FROM PROGRAM, which allows execution of system shell commands directly from an SQL query. By appropriately manipulating the SQL query passed to this endpoint, an attacker can achieve full code execution on the target server.
An attacker can execute arbitrary system commands on the server hosting Hasura GraphQL Engine, leading to complete system compromise, data exfiltration, and potential lateral movement within the internal network.
Apply patches available from the vendor according to the references provided. Additionally, it is recommended to restrict access to the run_sql endpoint exclusively to trusted, authenticated users and implement appropriate firewall rules blocking unauthorized access to the GraphQL interface.
Hasura GraphQL Engine version 1.3.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHasura Graphql Engine
APPHasura1.3.3
Related vulnerabilities
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service...
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has ...
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres bac...
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying J...
Hasura to produkt open-source oferujący użytkownikom GraphQL lub REST API. Przed wersjami 2.49.2 i 2.45.5 użyt...