[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-24407Date: (C)2022-02-25   (M)2024-02-06


In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 6.5
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-5087
FEDORA-2022-8cc64f73d0
FEDORA-2022-e33e824d37
FEDORA-2022-f9642fab70
N/A
https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html
http://www.openwall.com/lists/oss-security/2022/02/23/4
https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst
https://security.netapp.com/advisory/ntap-20221007-0003/
https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28

CPE    1
cpe:/o:debian:debian_linux:9.0
CWE    1
CWE-89
OVAL    28
oval:org.secpod.oval:def:506710
oval:org.secpod.oval:def:78392
oval:org.secpod.oval:def:606108
oval:org.secpod.oval:def:78424
...

© SecPod Technologies