ORNL / DataFed

A Federated Scientific Data Management System
https://ornl.github.io/DataFed/
Other
18 stars 14 forks source link

Core - Security Issues Identified by Synack #795

Closed dvstans closed 2 years ago

dvstans commented 2 years ago

Several AQL injection flaws have been identified by Synack that allow arbitrary AQL to be run in the DB microservice. These issues are being tracked in the ORNL issue tracking system.

dvstans commented 2 years ago

These are fixed, along with two additional issues that were reported later.