CVE-2018-14623: SQL Injection
Published Dec 13, 2018
·Updated
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
Affected Software
1 affected component
theforeman katello>=3.10.0
Event History
Dec 13, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-14623?
CVE-2018-14623 is a SQL injection vulnerability found in katello's errata-related API.
2
How does CVE-2018-14623 work?
An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs.
3
What is the severity of CVE-2018-14623?
CVE-2018-14623 has a severity rating of 4.3 (medium).
4
Which versions of katello are affected by CVE-2018-14623?
Version 3.10 and older of katello are vulnerable to CVE-2018-14623.
5
Is there a fix for CVE-2018-14623?
There is no known fix for CVE-2018-14623 at this time.