CVE-2018-14623
katello: SQL inject in errata-related REST API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
Se ha encontrado un error de inyección SQL en la API relacionada con erratas de katello. Un atacante remoto autenticado puede manipular datos de entrada para forzar una consulta SQL mal formada a la base de datos del backend, lo que filtrará ID internas. Este problema se relaciona con una solución incompleta para CVE-2016-3072. Las versiones 3.10 y anteriores son vulnerables.
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-27 CVE Reserved
- 2018-12-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-209: Generation of Error Message Containing Sensitive Information
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106224 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14623 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2018-14623 | 2018-02-21 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1623719 | 2018-02-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Theforeman Search vendor "Theforeman" | Katello Search vendor "Theforeman" for product "Katello" | >= 3.10.0 Search vendor "Theforeman" for product "Katello" and version " >= 3.10.0" | - |
Affected
|