PT-2020-11960 · Yubico · Yubikey Validation Server
Published
2020-03-05
·
Updated
2020-03-13
·
CVE-2020-10184
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
YubiKey Validation Server versions prior to 2.40
Description
The issue concerns a denial of service, potentially related to SQL injection, due to the verify endpoint not checking the length of SQL queries in the YubiKey Validation Server. This could allow remote attackers to exploit the service. The problem is relevant to self-hosted OTP validation services, not YubiCloud.
Recommendations
For versions prior to 2.40, update to version 2.40 or later to resolve the issue. As a temporary workaround, consider restricting access to the verify endpoint to minimize the risk of exploitation.
Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yubikey Validation Server