A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.debezium:debezium-connector-mysql(Maven) | 0 | 2.3.0.Alpha1 | N/A |
| io.debezium:debezium-connector-sqlserver(Maven) | 0 | 2.3.0.Alpha1 | N/A |
| io.debezium:debezium-core(Maven) | 0 | 2.3.0.Alpha1 | N/A |
CVSS Metrics