CVE Vulnerabilities

CVE-2023-31847

Published: May 17, 2023 | Modified: Jan 22, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.

Affected Software

NameVendorStart VersionEnd Version
DavinciDavinci_project0.3.0-rc (including)0.3.0-rc (including)

References