CVE-2022-45932: SQL Injection
Published Nov 27, 2022
·Updated
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.
Affected Software
4 affected components
linuxfoundation Opendaylight=0.15.0
linuxfoundation Opendaylight=0.15.6
linuxfoundation Opendaylight=0.16.0
linuxfoundation Opendaylight=0.16.4
Remediation
Patch Available
Patch Available
Event History
Nov 27, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45932?
CVE-2022-45932 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2022-45932?
To fix CVE-2022-45932, upgrade to OpenDaylight version 0.16.5 or later, where the vulnerability is resolved.
3
What software versions are affected by CVE-2022-45932?
CVE-2022-45932 affects OpenDaylight versions 0.15.0, 0.15.6, 0.16.0, and 0.16.4.
4
What impact does CVE-2022-45932 have?
CVE-2022-45932 allows an attacker to perform SQL injection through the deleteRole function in the RoleStore.
5
Is CVE-2022-45932 related to OpenDaylight APIs?
Yes, CVE-2022-45932 is specifically related to the /auth/v1/roles/ API interface in OpenDaylight.