{"id":"GHSA-v5wf-jg37-r9m5","summary":"SQLpage vulnerable to public exposure of database credentials","details":"### Impact\n\nIf\n - you are using a SQLPage version older than v0.11.1 \n - your SQLPage instance is exposed publicly\n - the database connection string is specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable)\n - the web_root is the current working directory (the default)\n - your database is exposed publicly\n\nthen an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly.\n\n### Patches\n\nUpgrade to [v0.11.1](https://github.com/lovasoa/SQLpage/releases/tag/v0.11.1) as soon as possible.\n\n### Workarounds\n\nIf you cannot upgrade immediately:\n\n - Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions.\n - Using a different [web root](https://github.com/lovasoa/SQLpage/blob/main/configuration.md) (that is not a parent of the SQLPage configuration directory) fixes the issue.\n - And in any case, you should generally avoid exposing your database publicly \n\n### References\n\nhttps://github.com/lovasoa/SQLpage/issues/89\n","aliases":["CVE-2023-42454"],"modified":"2026-09-10T03:50:03.303288108Z","published":"2023-09-21T17:10:06Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-09-21T17:10:06Z","nvd_published_at":"2023-09-18T22:15:47Z","cwe_ids":["CWE-200"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/lovasoa/SQLpage/security/advisories/GHSA-v5wf-jg37-r9m5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42454"},{"type":"WEB","url":"https://github.com/lovasoa/SQLpage/issues/89"},{"type":"PACKAGE","url":"https://github.com/lovasoa/SQLpage"},{"type":"WEB","url":"https://github.com/lovasoa/SQLpage/releases/tag/v0.11.1"}],"affected":[{"package":{"name":"sqlpage","ecosystem":"crates.io","purl":"pkg:cargo/sqlpage"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-v5wf-jg37-r9m5/GHSA-v5wf-jg37-r9m5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}