CVE-2022-24407
24.02.2022, 15:15
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
| Vendor | Product | Version |
|---|---|---|
| cyrusimap | cyrus-sasl | 2.1.17 ≤ 𝑥 ≤ 2.1.27 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | active_iq_unified_manager | - |
| netapp | ontap_select_deploy_administration_utility | - |
| oracle | communications_cloud_native_core_console | 22.2.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cyrus-sasl2 |
|
References