Advisories for Maven/Com.yahoo.elide/Elide-Core package

2022

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A column that requires a client provided parameter), and a parameterized column of type TEXT. There is the potential for a hacker to provide a carefully crafted query that would bypass server side authorization filters through SQL injection. A …

2020