← Back to browse · API

CVE-2023-30625

Severity
HIGH
CVSS
8.8
EPSS
0.85825
Risk score
65.24
CISA KEV
No
PoC
No
Published
2023-06-16
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-2479, GHSA-3JMM-F6JJ-RCC3
Products
rudderlabs:rudder-server < 1.3.0-rc.1
Sources
euvd EUVD-2024-2479

Description

rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.

References