Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24407

Опубликовано: 22 фев. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

A flaw was found in the SQL plugin shipped with Cyrus SASL. The vulnerability occurs due to failure to properly escape SQL input and leads to an improper input validation vulnerability. This flaw allows an attacker to execute arbitrary SQL commands and the ability to change the passwords for other accounts allowing escalation of privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9cyrus-saslNot affected
Red Hat JBoss Enterprise Application Platform 6cyrus-saslOut of support scope
Red Hat Enterprise Linux 6 Extended Lifecycle Supportcyrus-saslFixedRHSA-2022:078008.03.2022
Red Hat Enterprise Linux 7cyrus-saslFixedRHSA-2022:066624.02.2022
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2022:065823.02.2022
Red Hat Enterprise Linux 8cyrus-saslFixedRHSA-2022:065823.02.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionscyrus-saslFixedRHSA-2022:073002.03.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportcyrus-saslFixedRHSA-2022:073102.03.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportcyrus-saslFixedRHSA-2022:066824.02.2022
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2022:126307.04.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2055326cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands

EPSS

Процентиль: 66%
0.0053
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVSS3: 8.8
nvd
больше 3 лет назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVSS3: 8.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.8
debian
больше 3 лет назад

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does ...

suse-cvrf
больше 3 лет назад

Security update for cyrus-sasl

EPSS

Процентиль: 66%
0.0053
Низкий

8.8 High

CVSS3