pact_broker is vulnerable to SQL Injection
87
High Risk
The tag deletion service in lib/pact_broker/tags/service.rb interpolates the URL supplied tag_name into a raw DELETE statement and runs it through Sequel::Database#run. A crafted tag name can close the string literal and append stacked SQL statements that read, change, or drop tables and forge verification results used by deployment gates. The fix replaces the interpolated query with a Sequel dataset condition that binds the tag name as a literal value.
You are affected if you are using a version that falls within the vulnerable range.
pact_broker is vulnerable to SQL Injection in versions 2.20.0 - 2.120.0.
Upgrade the pact_broker library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.