SCA: security update for github.com/lf-edge/ekuiper/v2 (GHSA-526j-mv3p-f4vv)

critical Tenable Self-Hosted Container Security Plugin ID 428624

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-
constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the
getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to
execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in
an API request. Exploitation can lead to data theft, corruption, or deletion, and full database
compromise. This is fixed in version 2.2.1. (CVE-2025-54379)

See Also

https://github.com/advisories/GHSA-526j-mv3p-f4vv

Plugin Details

Severity: Critical

ID: 428624

Version: Revision 1.16

Type: Local

Family: SCA Checks

Published: 7/24/2025

Updated: 6/30/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.17

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-54379

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/24/2025

Vulnerability Publication Date: 7/24/2025

Reference Information

CVE: CVE-2025-54379

cwe: CWE-89