Debezium database connector has a script injection vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 17, 2024
to the GitHub Advisory Database
•
Updated Nov 18, 2024
Description
Published by the National Vulnerability Database
Nov 17, 2024
Published to the GitHub Advisory Database
Nov 17, 2024
Reviewed
Nov 18, 2024
Last updated
Nov 18, 2024
A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.
References