Описание
Due to a missing sanitization call in afsql_dd_run_query, syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
A flaw was found in syslog-ng. An attacker on an adjacent network can exploit a missing sanitization call in the afsql_dd_run_query function, leading to a SQL injection vulnerability. This vulnerability, when the SQL driver is manually configured, can result in a denial of service and allow for limited data manipulation from an untrusted source.
Отчет
This is an Important flaw in syslog-ng, as an attacker on an adjacent network could perform SQL injection. This vulnerability is not present in default configurations and requires the SQL driver to be manually configured, limiting its immediate impact on typical Red Hat deployments. Successful exploitation could lead to denial of service and limited data manipulation.
Меры по смягчению последствий
To mitigate this vulnerability, avoid manually configuring and enabling the syslog-ng SQL driver if it is not essential for your environment. If the SQL driver is required, restrict network access to the syslog-ng instance to trusted networks only, for example, by configuring firewall rules to limit connections to the syslog-ng port. Note that changes to network configurations or syslog-ng service settings may require a service reload or restart to take effect, which could temporarily interrupt logging services.
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...
EPSS
7.1 High
CVSS3