amazee.ai Private AI Provider
The module does not properly clean up search filters before using them to query the database. Anyone visiting the site could run malicious database commands to read any private information and change some data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses the module for intelligent search and exposes a specific type of search filter to visitors.
- Has it been used in attacksA working example has been published, so assume someone will try.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate amazee.ai Private AI Provider to 1.3.7 or 1.4.3, whichever branch you are on.
For developers: what the fix changed
The fix updates `PostgresProvider.php` to quote all Search API filter values using `prepareStringArrayForSql` regardless of their field type, preventing SQL injection. It also removes the insecure `prepareArrayForSql` method from `PostgresPgvectorClient.php`.
Also in this release The release also fixes an issue where key provisioning requests would time out and retry by increasing the timeout and disabling retries.
src/AmazeeIoApi/AmazeeClient.php+8 −3src/Vdb/Postgres/Plugin/VdbProvider/PostgresProvider.php+3 −8 fixsrc/Vdb/Postgres/PostgresPgvectorClient.php+0 −14 fix