Skip to content

security backport:#148 → 2.39#24149

Closed
netroms wants to merge 1 commit into
2.39from
security/2.39
Closed

security backport:#148 → 2.39#24149
netroms wants to merge 1 commit into
2.39from
security/2.39

Conversation

@netroms

@netroms netroms commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Security fixes backported to 2.39 for the coordinated release.

All commits GPG-signed; cherry-picked from the embargoed fixes and dry-run-verified clean against this branch. For the security release.

AI Assisted

…tion

The filter column name was concatenated raw into the generated WHERE
clause in DefaultSqlViewService.getFilterQuery, mirroring the same
shape that getCriteriaSqlClause already handles correctly via
statementBuilder.columnQuote(). Two independent reports demonstrate
the missed sink is exploitable for arbitrary SQL execution by any
authenticated user with read access to a SQL View:

- GHSA-pwmg-mvjw-4m23 — error-based exfil via CAST((subquery) AS int)
- internal report — UNION SELECT smuggled through the column-name slot

Wrapping the column name with statementBuilder.columnQuote() turns the
whole user-supplied string into a single Postgres identifier, which
Postgres rejects at parse time when it doesn't exist — preventing the
inner SQL from being evaluated. This is exactly the defense already
in place for the parallel sink in getCriteriaSqlClause.

Note: the master/2.40-2.42 backports use SqlUtils.quote() and ship
companion regression tests in SqlViewControllerIntegrationTest. On
2.39 the matching defense API is statementBuilder.columnQuote() and
the regression test class does not exist, so only the fix is applied.

AI Assisted

Refs GHSA-pwmg-mvjw-4m23, DHIS2-21425
@sonarqubecloud

sonarqubecloud Bot commented Jun 9, 2026

Copy link
Copy Markdown

@netroms

netroms commented Jun 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #24172, which carries #22253 + #148 and closes both SQLi slots (value + column-name) in DefaultSqlViewService.getFilterQuery on 2.39. Closing this #148-only PR.

@netroms netroms closed this Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants