6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter
ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count() and list()) interpolates the user-supplied tag KEY directly into a raw SQL fragment via Rust's format!() macro (`dsl::sql::<Bool>(&format!("device.tags->>'{}' =", k)).bind::<Text, _>(v)`), while only the tag VALUE is safely parameter-bound via Diesel's .bind(). An authenticated user with device-list access can inject SQL via a crafted tag key when the SQLite backend (chirpstack-sqlite package) is in use; the PostgreSQL backend is unaffected as it uses Diesel's native JSONB containment operator instead of raw SQL string formatting.
References
Affected products
- =<4.19.0-test.5
Matching in nixpkgs
pkgs.chirpstack-rest-api
gRPC API to REST proxy for Chirpstack
pkgs.chirpstack-fuota-server
FUOTA server which can be used together with ChirpStack Application Server
-
nixos-unstable 3.0.0-test.4-unstable-2025-08-26
- nixpkgs-unstable 3.0.0-test.4-unstable-2025-08-26
- nixos-unstable-small 3.0.0-test.4-unstable-2025-08-26
-
nixos-26.05 3.0.0-test.4-unstable-2025-08-26
- nixos-26.05-small 3.0.0-test.4-unstable-2025-08-26
- nixpkgs-26.05-darwin 3.0.0-test.4-unstable-2025-08-26
pkgs.chirpstack-gateway-mesh
Turn LoRa gateways into relays for extending the range of LoRa networks
pkgs.chirpstack-concentratord
Concentrator HAL daemon for LoRa gateways
pkgs.chirpstack-udp-forwarder
UDP packet-forwarder for the ChirpStack Concentratord
pkgs.chirpstack-gateway-bridge
Gateway Bridge abstracts Packet Forwarder protocols into Protobuf or JSON over MQTT
pkgs.chirpstack-mqtt-forwarder
Forwarder which can be installed on the gateway to forward LoRa data over MQTT
pkgs.python313Packages.chirpstack-api
ChirpStack gRPC API message and service wrappers for Python
Package maintainers
-
@stv0g Steffen Vogel <post@steffenvogel.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>