CVE-2022-24407
Published on: Not Yet Published
Last Modified on: 11/07/2022 05:28:00 PM UTC
Certain versions of Cyrus-sasl from Cyrusimap contain the following vulnerability:
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
- CVE-2022-24407 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cyrus SASL 2.1.x Release Notes — Cyrus SASL 2.1.28 documentation | www.cyrusimap.org text/html |
![]() |
cyrus-sasl/index.rst at fdcd13ceaef8de684dc69008011fa865c5b4a3ac · cyrusimap/cyrus-sasl · GitHub | github.com text/html |
![]() |
[SECURITY] [DLA 2931-1] cyrus-sasl2 security update | lists.debian.org text/html |
![]() |
oss-security - Fwd: Cyrus-SASL 2.1.28 released [fixes CVE-2022-24407 & CVE-2019-19906] | www.openwall.com text/html |
![]() |
[SECURITY] Fedora 36 Update: cyrus-sasl-2.1.27-18.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
CVE-2022-24407 Cyrus SASL Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
[SECURITY] Fedora 35 Update: cyrus-sasl-2.1.27-14.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 34 Update: cyrus-sasl-2.1.27-9.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Debian -- Security Information -- DSA-5087-1 cyrus-sasl2 | www.debian.org Depreciated Link text/html |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
Related QID Numbers
- 159673 Oracle Enterprise Linux Security Update for cyrus-sasl (ELSA-2022-0658)
- 159677 Oracle Enterprise Linux Security Update for cyrus-sasl (ELSA-2022-0666)
- 159725 Oracle Enterprise Linux Security Update for cyrus-sasl (ELSA-2022-9239)
- 179093 Debian Security Update for cyrus-sasl2 (DSA 5087-1)
- 179102 Debian Security Update for cyrus-sasl2 (DLA 2931-1)
- 198675 Ubuntu Security Notification for Cyrus SASL Vulnerability (USN-5301-1)
- 240107 Red Hat Update for cyrus-sasl (RHSA-2022:0658)
- 240111 Red Hat Update for cyrus-sasl (RHSA-2022:0668)
- 240113 Red Hat Update for cyrus-sasl (RHSA-2022:0666)
- 240118 Red Hat Update for cyrus-sasl (RHSA-2022:0731)
- 240439 Red Hat Update for cyrus-sasl (RHSA-2022:0730)
- 257159 CentOS Security Update for cyrus-sasl (CESA-2022:0666)
- 282461 Fedora Security Update for cyrus (FEDORA-2022-f9642fab70)
- 282466 Fedora Security Update for cyrus (FEDORA-2022-8cc64f73d0)
- 296057 Oracle Solaris 11.4 Support Repository Update (SRU) 44.113.4 Missing (bulletinapr2022)
- 353197 Amazon Linux Security Advisory for cyrus-sasl : ALAS2-2022-1758
- 353199 Amazon Linux Security Advisory for cyrus-sasl : ALAS-2022-1574
- 354287 Amazon Linux Security Advisory for cyrus-sasl : ALAS2022-2022-234
- 354448 Amazon Linux Security Advisory for cyrus-sasl : ALAS2022-2022-035
- 354563 Amazon Linux Security Advisory for cyrus-sasl : ALAS-2022-234
- 377044 Alibaba Cloud Linux Security Update for cyrus-sasl (ALINUX2-SA-2022:0015)
- 377136 Alibaba Cloud Linux Security Update for cyrus-sasl (ALINUX3-SA-2022:0013)
- 377910 Oracle MySQL Connectors 8.0.x Denial of Service (DoS) Vulnerability (CPUJAN2023)
- 390259 Oracle VM Server for x86 Security Update for cyrus-sasl (OVMSA-2022-0010)
- 500142 Alpine Linux Security Update for cyrus-sasl
- 671556 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1560)
- 671596 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1527)
- 671681 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1712)
- 671729 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1802)
- 671731 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1785)
- 671801 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1835)
- 671818 EulerOS Security Update for cyrus-sasl (EulerOS-SA-2022-1859)
- 690800 Free Berkeley Software Distribution (FreeBSD) Security Update for cyrus-sasl (022dde12-8f4a-11ec-83ac-080027415d17)
- 691034 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (dc49f6dc-99d2-11ed-86e9-d4c9ef517024)
- 751768 SUSE Enterprise Linux Security Update for cyrus-sasl (SUSE-SU-2022:0653-1)
- 751785 SUSE Enterprise Linux Security Update for cyrus-sasl (SUSE-SU-2022:0693-1)
- 751787 SUSE Enterprise Linux Security Update for cyrus-sasl (SUSE-SU-2022:0702-1)
- 751830 OpenSUSE Security Update for cyrus-sasl (openSUSE-SU-2022:0743-1)
- 751986 SUSE Enterprise Linux Security Update for cyrus-sasl (SUSE-SU-2022:0743-1)
- 753239 SUSE Enterprise Linux Security Update for cyrus-sasl (SUSE-SU-2022:14894-1)
- 900671 Common Base Linux Mariner (CBL-Mariner) Security Update for cyrus-sasl (8795)
- 901418 Common Base Linux Mariner (CBL-Mariner) Security Update for cyrus-sasl (8794-1)
- 940458 AlmaLinux Security Update for cyrus-sasl (ALSA-2022:0658)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cyrusimap | Cyrus-sasl | All | All | All | All |
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 34 | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Netapp | Ontap Select Deploy Administration Utility | - | All | All | All |
Application | Oracle | Communications Cloud Native Core Console | 22.2.0 | All | All | All |
Application | Oracle | Communications Cloud Native Core Network Function Cloud Native Environment | 22.2.0 | All | All | All |
Application | Oracle | Communications Cloud Native Core Security Edge Protection Proxy | 22.1.1 | All | All | All |
- cpe:2.3:a:cyrusimap:cyrus-sasl:*:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*:
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_console:22.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24407 | 2022-02-28 21:38:38 |