PT-2018-12622 · Red Hat · Katello
Mohamed Tehami
+1
·
Published
2018-12-13
·
Updated
2023-02-12
·
CVE-2018-14623
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
katello versions 3.10 and older
Description
A SQL injection flaw was found in katello's errata-related API, allowing an authenticated remote attacker to craft input data and force a malformed SQL query to the backend database. This can result in the leakage of internal IDs. The issue is related to an incomplete fix for a previous problem.
Recommendations
For versions 3.10 and older, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Katello