atlan-application-sdk is vulnerable to SQL Injection
50
Medium Risk
Affected versions of this package are vulnerable to SQL injection in the SQL metadata extraction filters. The include, exclude, and temp-table regex values supplied by callers are inserted directly into SQL templates without escaping, so a value containing a single quote can break out and inject arbitrary statements that execute against the source database.
You are affected if you are using a version that falls within the vulnerable range.
atlan-application-sdk is vulnerable to SQL Injection in versions 1.0.0 - 2.8.7.
Upgrade the atlan-application-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant