Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45932

Опубликовано: 16 нояб. 2022
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

A SQL injection issue was discovered in the AAA package of OpenDaylight. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used. This may allow a malicious user to execute arbitrary sql statements against the database.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)openstack-opendaylight-containerOut of support scope
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-neutron-server-opendaylightOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-89

EPSS

Процентиль: 39%
0.0018
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

CVSS3: 7.5
github
больше 3 лет назад

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

EPSS

Процентиль: 39%
0.0018
Низкий

6.8 Medium

CVSS3

Уязвимость CVE-2022-45932