{"schema_version":"1.7.3","id":"GHSA-7mwh-q3xm-qh6p","published":"2024-12-03T18:43:33Z","modified":"2026-08-07T08:12:23.040509879Z","aliases":["CVE-2024-53257","GO-2024-3306"],"summary":"Vitess allows HTML injection in /debug/querylogz & /debug/env","details":"### Summary\n\nThe `/debug/querylogz` and `/debug/env` pages for `vtgate` and `vttablet` do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will.\n\n### Details\n\nThese pages are rendered using `text/template` instead of rendering with a proper HTML templating engine.\n\n### PoC\n\nExecute any query where part of it is HTML markup, for example as part of a string. To make it easier to observe you might want to make sure the query takes a few seconds to complete, giving you time to refresh the status page. \n\nExample query that can trigger the issue:\n\n```sql\nUPDATE users\nSET\n    email = CONCAT(\"<img src=https://cataas.com/cat/says/oops>\", users.idUser, \"@xxx\")\nWHERE\n    email NOT LIKE '%xxx%' AND email != \"demo@xxx.com\"\n```\n\nResult: \n\n![image](https://github.com/user-attachments/assets/c583816b-157c-474e-bbed-152b3dc0372f)\n\n### Impact\n\nAnyone looking at the Vitess status page is affected. This would normally be owners / administrators of the Vitess cluster.\n\nAnyone that can influence what text show up in queries can trigger it. This would normally be pretty much everybody interacting with a system that uses Vitess as a backend.","affected":[{"package":{"name":"vitess.io/vitess","ecosystem":"Go","purl":"pkg:golang/vitess.io/vitess"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.21.0-rc1"},{"fixed":"0.21.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-7mwh-q3xm-qh6p/GHSA-7mwh-q3xm-qh6p.json"}},{"package":{"name":"vitess.io/vitess","ecosystem":"Go","purl":"pkg:golang/vitess.io/vitess"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.20.0-rc1"},{"fixed":"0.20.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-7mwh-q3xm-qh6p/GHSA-7mwh-q3xm-qh6p.json"}},{"package":{"name":"vitess.io/vitess","ecosystem":"Go","purl":"pkg:golang/vitess.io/vitess"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.19.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-7mwh-q3xm-qh6p/GHSA-7mwh-q3xm-qh6p.json"}}],"references":[{"type":"WEB","url":"https://github.com/vitessio/vitess/security/advisories/GHSA-7mwh-q3xm-qh6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53257"},{"type":"WEB","url":"https://github.com/vitessio/vitess/commit/2b71d1b5f8ca676beeab2875525003cd45096217"},{"type":"PACKAGE","url":"https://github.com/vitessio/vitess"}],"database_specific":{"cwe_ids":["CWE-79"],"github_reviewed":true,"github_reviewed_at":"2024-12-03T18:43:33Z","nvd_published_at":"2024-12-03T16:15:23Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}