CVE-2024-40120: SQL Injection
Published May 16, 2025
·Updated
seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstractsql/abstractsqlstore.go.
Affected Software
3 affected componentsFixes available
seaweedfs seaweedfs
go/github.com/seaweedfs/seaweedfs<0.0.0-20240625155419-9ac102336200
0.0.0-20240625155419-9ac102336200
seaweedfs seaweedfs=3.68
Event History
May 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-40120?
CVE-2024-40120 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2024-40120?
To fix CVE-2024-40120, update SeaweedFS to the latest version that addresses this vulnerability.
3
What versions of SeaweedFS are affected by CVE-2024-40120?
CVE-2024-40120 affects SeaweedFS version 3.68 and possibly earlier versions.
4
What are the potential impacts of CVE-2024-40120?
CVE-2024-40120 can allow attackers to execute arbitrary SQL queries, leading to unauthorized access and data manipulation.
5
Where can I find more information about CVE-2024-40120?
More information about CVE-2024-40120 can typically be found in security advisories and the SeaweedFS GitHub repository.