harness(gitness) registry webhook sort_order blind SQL injection
Harness open-source Gitness has a blind SQL injection in the registry webhook sort_order parameter.
Khashayar Fereidani disclosed a blind SQL injection in the sort_order parameter used when listing registry webhooks in Harness open source (Gitness). Gitness is a self-hosted platform for source control, pipelines, and artifact registries. The affected call is the registry API endpoint that lists a registry's webhooks. No CVE or in-the-wild exploitation is stated.
- Blind SQL injection is in the webhook sort_order parameter.
- Affected API lists webhooks for a Gitness registry.
- Gitness is Harness's self-hosted source, pipeline, and registry platform.
- No CVE or observed exploitation is mentioned.
Posted by Khashayar Fereidani on Sep 26 # harness registry webhook sort_order blind SQL injection https://fereidani.com/harness-registry-webhook-sortorder-blind-sql-injection https://fereidani.com/contact ## Description Harness open source (Gitness) is a self-hosted platform for source control, pipelines and artifact registries. The registry API lists the webhooks of a registry at `GET...
This source does not provide full text. Read it at seclists.org.