Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24407

Опубликовано: 22 фев. 2022
Источник: redhat
CVSS3: 8.8

Описание

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

A flaw was found in the SQL plugin shipped with Cyrus SASL. The vulnerability occurs due to failure to properly escape SQL input and leads to an improper input validation vulnerability. This flaw allows an attacker to execute arbitrary SQL commands and the ability to change the passwords for other accounts allowing escalation of privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9cyrus-saslNot affected
Red Hat JBoss Enterprise Application Platform 6cyrus-saslOut of support scope
Red Hat Enterprise Linux 6 Extended Lifecycle Supportcyrus-saslFixedRHSA-2022:078008.03.2022
Red Hat Enterprise Linux 7cyrus-saslFixedRHSA-2022:066624.02.2022
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2022:065823.02.2022
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2022:065823.02.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionscyrus-saslFixedRHSA-2022:073002.03.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportcyrus-saslFixedRHSA-2022:073102.03.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportcyrus-saslFixedRHSA-2022:066824.02.2022
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2022:126307.04.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2055326cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 4 года назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVSS3: 8.8
nvd
почти 4 года назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVSS3: 8.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 8.8
debian
почти 4 года назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does ...

suse-cvrf
почти 4 года назад

Security update for cyrus-sasl

8.8 High

CVSS3