First published: Wed Feb 16 2022(Updated: )
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cyrus-sasl | <0:2.1.23-16.el6_10 | 0:2.1.23-16.el6_10 |
redhat/cyrus-sasl | <0:2.1.26-24.el7_9 | 0:2.1.26-24.el7_9 |
redhat/cyrus-sasl | <0:2.1.27-6.el8_5 | 0:2.1.27-6.el8_5 |
redhat/cyrus-sasl | <0:2.1.27-2.el8_1 | 0:2.1.27-2.el8_1 |
redhat/cyrus-sasl | <0:2.1.27-2.el8_2 | 0:2.1.27-2.el8_2 |
redhat/cyrus-sasl | <0:2.1.27-6.el8_4 | 0:2.1.27-6.el8_4 |
redhat/redhat-virtualization-host | <0:4.3.22-20220330.1.el7_9 | 0:4.3.22-20220330.1.el7_9 |
debian/cyrus-sasl2 | 2.1.27+dfsg-1+deb10u2 2.1.27+dfsg-2.1+deb11u1 2.1.28+dfsg-10 2.1.28+dfsg1-3 | |
redhat/cyrus-sasl | <2.1.28 | 2.1.28 |
Cyrus SASL | >=2.1.17<=2.1.27 | |
Debian | =9.0 | |
Debian | =10.0 | |
Debian | =11.0 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp ONTAP Select Deploy | ||
oracle communications cloud native core console | =22.2.0 | |
oracle communications cloud native core network function cloud native environment | =22.2.0 | |
Oracle Communications Cloud Native Core Network Repository Function | =22.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2022-24407 is high (8.8).
The affected software of CVE-2022-24407 includes Cyrus SASL version 2.1.17 through 2.1.27.
CVE-2022-24407 occurs due to failure to properly escape SQL input in the SQL plugin shipped with Cyrus SASL.
The potential impact of CVE-2022-24407 is the execution of arbitrary SQL commands and the ability to change passwords for other accounts.
To fix CVE-2022-24407, update to Cyrus SASL version 2.1.28.