LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/lf-edge/ekuiper(Go) | 0 | 1.14.2 | N/A |
| ekuiper(PyPI) | 0 | 1.14.2 | N/A |
CVSS Metrics