Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14623

Опубликовано: 12 дек. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Subscription Asset ManagerkatelloWill not fix
Red Hat Satellite 6.3 for RHEL 7candlepinFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foremanFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-discovery-imageFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-installerFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-proxyFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-selinuxFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7hieraFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7katelloFixedRHSA-2018:033621.02.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-89->CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1623719katello: SQL inject in errata-related REST API

EPSS

Процентиль: 48%
0.00245
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 7 лет назад

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.

CVSS3: 4.3
github
больше 3 лет назад

katello SQL Injection vulnerability

EPSS

Процентиль: 48%
0.00245
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2018-14623