Skip to content

Fix SQL injection in get-host-dependencies#13868

Merged
murrant merged 1 commit intolibrenms:masterfrom
Jellyfrog:security/sql-injection-get-host-deps
Mar 24, 2022
Merged

Fix SQL injection in get-host-dependencies#13868
murrant merged 1 commit intolibrenms:masterfrom
Jellyfrog:security/sql-injection-get-host-deps

Conversation

@Jellyfrog
Copy link
Copy Markdown
Member

Thanks to raf at TNP Consultants for reporting it

Please note

Please read this information carefully. You can run ./lnms dev:check to check your code before submitting.

  • Have you followed our code guidelines?
  • If my Pull Request does some changes/fixes/enhancements in the WebUI, I have inserted a screenshot of it.
  • If my Pull Request makes discovery/polling/yaml changes, I have added/updated test data.

Testers

If you would like to test this pull request then please run: ./scripts/github-apply <pr_id>, i.e ./scripts/github-apply 5926
After you are done testing, you can remove the changes with ./scripts/github-remove. If there are schema changes, you can ask on discord how to revert.

@Jellyfrog Jellyfrog force-pushed the security/sql-injection-get-host-deps branch from ce28dad to c5d860e Compare March 22, 2022 21:46
@Jellyfrog
Copy link
Copy Markdown
Member Author

Untested

Thanks to raf at TNP Consultants for reporting it
@Jellyfrog Jellyfrog force-pushed the security/sql-injection-get-host-deps branch from c5d860e to 06292bf Compare March 23, 2022 17:35
@murrant murrant merged commit 4df7968 into librenms:master Mar 24, 2022
jerji pushed a commit to Beanfield/librenms that referenced this pull request Apr 14, 2022
Thanks to raf at TNP Consultants for reporting it
@librenms-bot
Copy link
Copy Markdown

This pull request has been mentioned on LibreNMS Community. There might be relevant details there:

https://community.librenms.org/t/22-4-0-changelog/18610/1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants