Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Monika security issue (SQL injection) #178

Open
matthieu637 opened this issue Oct 30, 2020 · 1 comment
Open

Monika security issue (SQL injection) #178

matthieu637 opened this issue Oct 30, 2020 · 1 comment

Comments

@matthieu637
Copy link

matthieu637 commented Oct 30, 2020

Hello,
The IT team of our university (also #165) informed us that there is a security issue with monika (SQL injection).

/monika/monika?job=-1%20OR%203*2*1=6%20AND%20000436=000436%20--%20

Hopefully, it's with the read-only user.

But still our server doesn't like it (postgresql process uses 100% CPU after that kind of request):
image

We are using the version 2.5.8~rc8-1 with postgresql 10.14-0ubuntu0.18.0.

@npf
Copy link
Contributor

npf commented Dec 5, 2020

Hello,

A patch (PR) would be very welcome.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants