First published: Wed Feb 16 2022(Updated: )
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cyrus-sasl | <0:2.1.23-16.el6_10 | 0:2.1.23-16.el6_10 |
redhat/cyrus-sasl | <0:2.1.26-24.el7_9 | 0:2.1.26-24.el7_9 |
redhat/cyrus-sasl | <0:2.1.27-6.el8_5 | 0:2.1.27-6.el8_5 |
redhat/cyrus-sasl | <0:2.1.27-2.el8_1 | 0:2.1.27-2.el8_1 |
redhat/cyrus-sasl | <0:2.1.27-2.el8_2 | 0:2.1.27-2.el8_2 |
redhat/cyrus-sasl | <0:2.1.27-6.el8_4 | 0:2.1.27-6.el8_4 |
redhat/redhat-virtualization-host | <0:4.3.22-20220330.1.el7_9 | 0:4.3.22-20220330.1.el7_9 |
debian/cyrus-sasl2 | 2.1.27+dfsg-1+deb10u2 2.1.27+dfsg-2.1+deb11u1 2.1.28+dfsg-10 2.1.28+dfsg1-3 | |
redhat/cyrus-sasl | <2.1.28 | 2.1.28 |
Apple macOS Catalina | >=2.1.17<=2.1.27 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
NetApp ONTAP Select Deploy administration utility | ||
Oracle Communications Cloud Native Core Console | =22.2.0 | |
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =22.2.0 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =22.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2022-24407 is high (8.8).
The affected software of CVE-2022-24407 includes Cyrus SASL version 2.1.17 through 2.1.27.
CVE-2022-24407 occurs due to failure to properly escape SQL input in the SQL plugin shipped with Cyrus SASL.
The potential impact of CVE-2022-24407 is the execution of arbitrary SQL commands and the ability to change passwords for other accounts.
To fix CVE-2022-24407, update to Cyrus SASL version 2.1.28.