In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 06:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2022/02/23/4 - Mailing List, Patch, Third Party Advisory | |
References | () https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst - Release Notes, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/ - | |
References | () https://security.netapp.com/advisory/ntap-20221007-0003/ - Third Party Advisory | |
References | () https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28 - Release Notes, Vendor Advisory | |
References | () https://www.debian.org/security/2022/dsa-5087 - Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory |
07 Nov 2023, 03:44
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2022-02-24 15:15
Updated : 2024-11-21 06:50
NVD link : CVE-2022-24407
Mitre link : CVE-2022-24407
CVE.ORG link : CVE-2022-24407
JSON object : View
Products Affected
oracle
- communications_cloud_native_core_network_function_cloud_native_environment
- communications_cloud_native_core_security_edge_protection_proxy
- communications_cloud_native_core_console
netapp
- ontap_select_deploy_administration_utility
- active_iq_unified_manager
cyrusimap
- cyrus-sasl
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')